Man vs. Machine: Practical Adversarial Detection of Malicious Crowdsourcing Workers

Man vs. Machine: Practical Adversarial Detection of Malicious Crowdsourcing Workers
复制标题

DOI:
--
复制
发表时间:
2014-08
期刊:
--
影响因子:
--
通讯作者:
G. Wang;Tianyi Wang;Haitao Zheng;Ben Y. Zhao
G. Wang;Tianyi Wang;Haitao Zheng;Ben Y. Zhao
中科院分区:
其他
文献类型:
--
作者:
G. Wang;Tianyi Wang;Haitao Zheng;Ben Y. Zhao

文献摘要

被引文献

相似文献

最近在安全和系统方面的工作已经包括使用机器学习(ML)技术来识别不当行为,例如社交网络中的电子邮件垃圾邮件和假(Sybil)用户。然而,ML模型通常来自固定的数据集,必须定期重新训练。在对抗性环境中,攻击者可以通过修改他们的行为来适应,甚至通过污染训练数据来破坏ML模型。在本文中,我们在检测恶意众包系统的背景下对机器学习模型进行了对抗性攻击的实证研究,其中网站将付费用户与愿意进行恶意活动的工作人员联系起来。通过使用人工,这些系统可以轻松地绕过部署的安全机制,例如CAPTCHA。我们收集了一个恶意工作者在微博(中国的Twitter)上积极执行任务的数据集,并使用它来开发基于ML的检测器。我们发现,传统的机器学习技术在检测方面是准确的(95%-99%),但很容易受到对抗性攻击,包括简单的逃避攻击(工人修改他们的行为)和强大的中毒攻击(管理员篡改训练集)。我们通过使用地面真实数据在一系列实际对抗模型中评估ML分类器的鲁棒性来量化ML分类器的鲁棒性。我们的分析提供了对ML模型的实际对抗性攻击的详细了解,并帮助防御者在ML检测器的设计和配置中做出明智的决定。
Recent work in security and systems has embraced the use of machine learning (ML) techniques for identifying misbehavior, e.g. email spam and fake (Sybil) users in social networks. However, ML models are typically derived from fixed datasets, and must be periodically retrained. In adversarial environments, attackers can adapt by modifying their behavior or even sabotaging ML models by polluting training data. In this paper, we perform an empirical study of adversarial attacks against machine learning models in the context of detecting malicious crowdsourcing systems, where sites connect paying users with workers willing to carry out malicious campaigns. By using human workers, these systems can easily circumvent deployed security mechanisms, e.g. CAPTCHAs. We collect a dataset of malicious workers actively performing tasks on Weibo, China's Twitter, and use it to develop ML-based detectors. We show that traditional ML techniques are accurate (95%-99%) in detection but can be highly vulnerable to adversarial attacks, including simple evasion attacks (workers modify their behavior) and powerful poisoning attacks (where administrators tamper with the training set). We quantify the robustness of ML classifiers by evaluating them in a range of practical adversarial models using ground truth data. Our analysis provides a detailed look at practical adversarial attacks on ML models, and helps defenders make informed decisions in the design and configuration of ML detectors.