ROOM: Adversarial Machine Learning Attacks Under Real-Time Constraints

ROOM: Adversarial Machine Learning Attacks Under Real-Time Constraints
复制标题

ROOM:实时约束下的对抗性机器学习攻击

DOI:
--
复制
发表时间:
2022
期刊:
IEEE International Joint Conference on Neural Network
影响因子:
--
通讯作者:
Ihsen Alouani
Ihsen Alouani
中科院分区:
--
文献类型:
--
作者:
Amira Guesmi;Khaled N. Khasawneh;Nael B. Abu;Ihsen Alouani

文献摘要

参考文献

被引文献

相似文献

深度学习的进步使其有了广泛的应用前景。然而,这些系统容易受到对抗性攻击;对抗性地对它们的输入进行干扰可能会导致它们错误分类。大多数最先进的对抗性攻击生成算法主要集中在控制噪声大小,使其无法被检测到。执行时间是这些攻击的次要考虑因素,基本假设是没有时间限制。然而,即时对抗性攻击(攻击者机会主义地在运行中生成对抗性示例)代表了更严重的威胁,特别是针对实时应用程序。因此,本文引入了一个新的问题:如何在实时约束下系统地产生对抗噪声?了解这个问题可以提高我们对这些攻击对实时系统构成的威胁的理解,并为未来的防御提供安全评估基准。因此,首先,我们对对抗生成算法进行运行时分析。我们的分析表明,通用攻击会在没有在线开销的情况下离线产生一般攻击。然而,由于其通用性,其成功率有限。相比之下,针对特定输入的在线算法在计算上很昂贵,因此在时间限制下不合适。因此,我们提出了ROOM,一种新颖的实时在线-离线攻击构建模型,其中离线组件预热在线算法,使得在时间限制下产生高度成功的攻击成为可能。我们的研究结果表明,ROOM可以在实时约束下实现高攻击成功率,对抗攻击生成速度比最先进的方法快90倍。例如,ROOM在MNIST上实现100%的对抗性攻击成功率,吞吐量高达1250帧/秒(FPS),在CIFAR-10上200帧/秒成功率超过60%,在ImageNet上16帧/秒成功率超过60%。
Advances in deep-learning have enabled a wide range of promising applications. However, these systems are vulnerable to adversarial attacks; adversarially crafted pertur-bations to their inputs could cause them to misclassify. Most state-of-the-art adversarial attack generation algorithms focus primarily on controlling the noise magnitude to make it undetectable. The execution time is a secondary consideration for these attacks and the underlying assumption is that there are no time constraints. However, just-in-time adversarial attacks where an attacker opportunistically generates adversarial examples on-the-fly represent an even more critical threat, especially against real-time applications. Therefore, this paper introduces a new problem: how to systematically generate adversarial noise under real-time constraints? Understanding this problem improves our understanding of the threat these attacks pose to real-time systems and provides security evaluation benchmarks for future defenses. Therefore, first, we conduct a run-time analysis of adversarial generation algorithms. Our analysis show that universal attacks produce a general attack offline, with no online overhead. However, their success rate is limited because of their generality. In contrast, online algorithms, which target a specific input, are computationally expensive, making them inappropriate under time constraints. Thus, we propose ROOM, a novel Real-time Online-Offline attack construction Model where an offline component warms up the online algorithm, making it possible to generate highly successful attacks under time constraints. Our results show that ROOM can achieve high attack success rates under real-time constraints with up to 90x faster adversarial attack generation than state-of-the-art methods. For example, ROOM achieves 100% adversarial attack success rate on MNIST with a throughput of up to 1250 frame per second (FPS), more than 60% success rate with 200 FPS on CIFAR-10 and 60% with 16 FPS on ImageNet.
DOI: 10.1145/3372297.3423348
发表时间: 2020-10
期刊: Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Zhuohang Li;Yi Wu;Jian Liu;Yingying Chen;Bo Yuan
通讯作者: Zhuohang Li;Yi Wu;Jian Liu;Yingying Chen;Bo Yuan
DOI: 10.1109/tnnls.2018.2886017
发表时间: 2019-09-01
影响因子: 10.4
作者:
Yu, Xiaoyong;He, Pan;Li, Xiaolin
通讯作者: Li, Xiaolin