Backdoor attacks against learning systems

Backdoor attacks against learning systems
复制标题

DOI:
10.1109/cns.2017.8228656
复制
发表时间:
2017-10
期刊:
2017 IEEE Conference on Communications and Network Security (CNS)
影响因子:
--
通讯作者:
Yujie Ji;Xinyang Zhang-;Ting Wang
Yujie Ji;Xinyang Zhang-;Ting Wang
中科院分区:
其他
文献类型:
--
作者:
Yujie Ji;Xinyang Zhang-;Ting Wang

文献摘要

被引文献

相似文献

今天的许多机器学习(ML)系统都是由一系列原始学习模块(PLM)组成的。PLM的大量使用大大简化和加快了系统开发周期。然而,由于大多数PLM都是由第三方提供和维护的,它们缺乏标准化或监管,这会带来深刻的安全问题。在本文中,我们第一次证明了潜在的有害PLM会对ML供电系统的安全性造成巨大威胁。我们提出了一个一般类的后门攻击,其中恶意制作的PLM触发主机系统故障以可预测的方式,一旦预定义的条件存在。我们通过实证研究最先进的皮肤癌筛查系统来验证这种攻击的可行性。例如,在没有任何关于系统是如何构建或训练的先验知识的情况下,它极有可能迫使系统误诊目标受害者。此外,我们讨论了基于PLM的攻击成功背后的根本原因,这些原因指向当今ML模型的特征:高维性,非线性和非凸性。因此,这个问题似乎是整个行业的问题。
Many of today's machine learning (ML) systems are composed by an array of primitive learning modules (PLMs). The heavy use of PLMs significantly simplifies and expedites the system development cycles. However, as most PLMs are contributed and maintained by third parties, their lack of standardization or regulation entails profound security implications. In this paper, for the first time, we demonstrate that potentially harmful PLMs incur immense threats to the security of ML-powered systems. We present a general class of backdoor attacks in which maliciously crafted PLMs trigger host systems to malfunction in a predictable manner once predefined conditions are present. We validate the feasibility of such attacks by empirically investigating a state-of-the-art skin cancer screening system. For example, it proves highly probable to force the system to misdiagnose a targeted victim, without any prior knowledge about how the system is built or trained. Further, we discuss the root causes behind the success of PLM-based attacks, which point to the characteristics of today's ML models: high dimensionality, non-linearity, and non-convexity. Therefore, the issue seems industry-wide.