ConAML: Constrained Adversarial Machine Learning for Cyber-Physical Systems

ConAML: Constrained Adversarial Machine Learning for Cyber-Physical Systems
复制标题

DOI:
10.1145/3433210.3437513
复制
发表时间:
2020-03
期刊:
Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Jiangnan Li;Jin Young Lee;Yingyuan Yang;Jinyuan Sun;K. Tomsovic
Jiangnan Li;Jin Young Lee;Yingyuan Yang;Jinyuan Sun;K. Tomsovic
中科院分区:
其他
文献类型:
--
作者:
Jiangnan Li;Jin Young Lee;Yingyuan Yang;Jinyuan Sun;K. Tomsovic

文献摘要

相似文献

最近的研究表明,表面上训练有素的机器学习(ML)模型非常容易受到对抗性例子的影响。随着机器学习技术正在成为研究文献中网络物理系统(CPS)应用的流行解决方案,这些应用程序的安全性受到关注。然而,目前对抗性机器学习(AML)的研究主要集中在纯网络空间领域。对抗性示例可能给 CPS 应用带来的风险尚未得到充分研究。特别是,由于数据源的分布式特性和CPS所施加的固有物理约束,先前网络空间研究中广泛使用的威胁模型和最先进的AML算法变得不可行。我们通过提出约束对抗性机器学习(ConAML)来研究机器学习在 CPS 中应用的潜在漏洞,它生成满足物理系统内在约束的对抗性示例。我们首先总结了 CPS 中的 AML 与现有网络空间系统中的 AML 之间的差异,并提出了 ConAML 的通用威胁模型。然后,我们设计了一种尽力而为的搜索算法,以迭代地生成具有线性物理约束的对抗性示例。我们通过模拟两种典型的 CPS(电网和水处理系统)来评估我们的算法。结果表明,我们的 ConAML 算法可以有效地生成对抗性示例,即使在实际约束下,也会显着降低 ML 模型的性能。
Recent research demonstrated that the superficially well-trained machine learning (ML) models are highly vulnerable to adversarial examples. As ML techniques are becoming a popular solution for cyber-physical systems (CPSs) applications in research literatures, the security of these applications is of concern. However, current studies on adversarial machine learning (AML) mainly focus on pure cyberspace domains. The risks the adversarial examples can bring to the CPS applications have not been well investigated. In particular, due to the distributed property of data sources and the inherent physical constraints imposed by CPSs, the widely-used threat models and the state-of-the-art AML algorithms in previous cyberspace research become infeasible. We study the potential vulnerabilities of ML applied in CPSs by proposing Constrained Adversarial Machine Learning (ConAML), which generates adversarial examples that satisfy the intrinsic constraints of the physical systems. We first summarize the difference between AML in CPSs and AML in existing cyberspace systems and propose a general threat model for ConAML. We then design a best-effort search algorithm to iteratively generate adversarial examples with linear physical constraints. We evaluate our algorithms with simulations of two typical CPSs, the power grids and the water treatment system. The results show that our ConAML algorithms can effectively generate adversarial examples which significantly decrease the performance of the ML models even under practical constraints.