Wild patterns: Ten years after the rise of adversarial machine learning

Wild patterns: Ten years after the rise of adversarial machine learning
复制标题

DOI:
10.1016/j.patcog.2018.07.023
复制
发表时间:
2018-12-01
影响因子:
8
通讯作者:
Roli, Fabio
Roli, Fabio
中科院分区:
计算机科学1区
文献类型:
--
作者:
Biggio, Battista;Roli, Fabio

文献摘要

被引文献

相似文献

基于学习的模式分类器,包括深度网络,在从计算机视觉到网络安全的几个应用领域表现出了令人印象深刻的性能。然而,也有研究表明,在训练或测试时精心设计的对抗性输入扰动很容易颠覆他们的预测。在对抗性机器学习的研究领域中,机器学习对这种狂野模式(也称为对抗性示例)的脆弱性以及合适的对策的设计已经得到了研究。在这项工作中,我们全面概述了这一研究领域在过去十年和以后的发展,从早期关于非深度学习算法安全性的开创性工作到最近旨在了解计算机视觉和网络安全任务背景下深度学习算法的安全属性的工作。我们报告了这些明显不同的工作之间的有趣联系,强调了与机器学习算法的安全评估相关的常见误解。我们回顾了为此定义的主要威胁模型和攻击,并讨论了当前工作的主要限制,以及未来设计更安全的学习算法的相应挑战。(C)2018爱思唯尔有限公司。保留所有权利。
Learning-based pattern classifiers, including deep networks, have shown impressive performance in several application domains, ranging from computer vision to cybersecurity. However, it has also been shown that adversarial input perturbations carefully crafted either at training or at test time can easily subvert their predictions. The vulnerability of machine learning to such wild patterns (also referred to as adversarial examples), along with the design of suitable countermeasures, have been investigated in the research field of adversarial machine learning. In this work, we provide a thorough overview of the evolution of this research area over the last ten years and beyond, starting from pioneering, earlier work on the security of non-deep learning algorithms up to more recent work aimed to understand the security properties of deep learning algorithms, in the context of computer vision and cybersecurity tasks. We report interesting connections between these apparently-different lines of work, highlighting common misconceptions related to the security evaluation of machine-learning algorithms. We review the main threat models and attacks defined to this end, and discuss the main limitations of current work, along with the corresponding future challenges towards the design of more secure learning algorithms. (C) 2018 Elsevier Ltd. All rights reserved.