ROOM: Adversarial Machine Learning Attacks Under Real-Time Constraints
ROOM: Adversarial Machine Learning Attacks Under Real-Time Constraints
复制标题
ROOM:实时约束下的对抗性机器学习攻击
DOI:
--
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Ihsen Alouani
中科院分区:
文献类型:
--
作者:
Amira Guesmi;Khaled N. Khasawneh;Nael B. Abu;Ihsen Alouani
Advances in deep-learning have enabled a wide range of promising applications. However, these systems are vulnerable to adversarial attacks; adversarially crafted pertur-bations to their inputs could cause them to misclassify. Most state-of-the-art adversarial attack generation algorithms focus primarily on controlling the noise magnitude to make it undetectable. The execution time is a secondary consideration for these attacks and the underlying assumption is that there are no time constraints. However, just-in-time adversarial attacks where an attacker opportunistically generates adversarial examples on-the-fly represent an even more critical threat, especially against real-time applications. Therefore, this paper introduces a new problem: how to systematically generate adversarial noise under real-time constraints? Understanding this problem improves our understanding of the threat these attacks pose to real-time systems and provides security evaluation benchmarks for future defenses. Therefore, first, we conduct a run-time analysis of adversarial generation algorithms. Our analysis show that universal attacks produce a general attack offline, with no online overhead. However, their success rate is limited because of their generality. In contrast, online algorithms, which target a specific input, are computationally expensive, making them inappropriate under time constraints. Thus, we propose ROOM, a novel Real-time Online-Offline attack construction Model where an offline component warms up the online algorithm, making it possible to generate highly successful attacks under time constraints. Our results show that ROOM can achieve high attack success rates under real-time constraints with up to 90x faster adversarial attack generation than state-of-the-art methods. For example, ROOM achieves 100% adversarial attack success rate on MNIST with a throughput of up to 1250 frame per second (FPS), more than 60% success rate with 200 FPS on CIFAR-10 and 60% with 16 FPS on ImageNet.
DOI:
10.1145/3372297.3423348
发表时间:
2020-10
期刊:
Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
Zhuohang Li;Yi Wu;Jian Liu;Yingying Chen;Bo Yuan
通讯作者:
Zhuohang Li;Yi Wu;Jian Liu;Yingying Chen;Bo Yuan
DOI:
10.1109/tnnls.2018.2886017
发表时间:
2019-09-01
影响因子:
10.4
作者:
Yu, Xiaoyong;He, Pan;Li, Xiaolin
通讯作者:
Li, Xiaolin