Measuring Equality in Machine Learning Security Defenses: A Case Study in Speech Recognition

Measuring Equality in Machine Learning Security Defenses: A Case Study in Speech Recognition
复制标题

DOI:
10.1145/3605764.3623911
复制
发表时间:
2023-02
期刊:
Proceedings of the 16th ACM Workshop on Artificial Intelligence and Security
影响因子:
--
通讯作者:
Luke E. Richards;Edward Raff;Cynthia Matuszek
Luke E. Richards;Edward Raff;Cynthia Matuszek
中科院分区:
其他
文献类型:
--
作者:
Luke E. Richards;Edward Raff;Cynthia Matuszek

文献摘要

相似文献

在过去的十年里,机器学习安全社区开发了无数针对逃避攻击的防御措施。在那个社区里,一个被忽视的问题是:这些防御是为谁辩护?这项工作考虑了保护学习系统的常见方法,以及安全防御如何导致不同子群体的性能不平等。我们勾勒出合适的奇偶度量进行分析,并通过机器学习安全方法的公平性影响的实证结果开始回答这个问题。我们发现,已提出的许多方法都会造成直接危害,如错误拒绝和健壮性训练带来的不平等好处。我们提出的衡量防御平等的框架可以应用于稳健训练的模型、基于预处理的防御和拒绝方法。我们确定了一组数据集,这些数据集具有以用户为中心的应用程序,并且计算成本合理,适合用于案例研究来衡量辩护的等价性。在我们的语音命令识别案例研究中,我们展示了这种对抗性训练和增强如何根据用户覆盖范围为不同性别、口音和年龄的社会亚群提供不平等但复杂的保护。我们比较了两种基于拒绝的防御机制:随机平滑和神经排斥,发现由于少数群体的抽样机制,随机平滑更公平。这是第一个研究语音域中对抗性稳健性的差异和基于拒绝的防御的公平性评估的工作。
Over the past decade, the machine learning security community has developed a myriad of defenses for evasion attacks. An understudied question in that community is: for whom do these defenses defend? This work considers common approaches to defending learned systems and how security defenses result in performance inequities across different sub-populations. We outline appropriate parity metrics for analysis and begin to answer this question through empirical results of the fairness implications of machine learning security methods. We find that many methods that have been proposed can cause direct harm, like false rejection and unequal benefits from robustness training. The framework we propose for measuring defense equality can be applied to robustly trained models, preprocessing-based defenses, and rejection methods. We identify a set of datasets with a user-centered application and a reasonable computational cost suitable for case studies in measuring the equality of defenses. In our case study of speech command recognition, we show how such adversarial training and augmentation have non-equal but complex protections for social subgroups across gender, accent, and age in relation to user coverage. We present a comparison of equality between two rejection-based defenses: randomized smoothing and neural rejection, finding randomized smoothing more equitable due to the sampling mechanism for minority groups. This represents the first work examining the disparity in the adversarial robustness in the speech domain and the fairness evaluation of rejection-based defenses.