Forgotten Siblings: Unifying Attacks on Machine Learning and Digital Watermarking

Forgotten Siblings: Unifying Attacks on Machine Learning and Digital Watermarking
复制标题

DOI:
10.1109/eurosp.2018.00041
复制
发表时间:
2018-04
期刊:
2018 IEEE European Symposium on Security and Privacy (EuroS&P)
影响因子:
--
通讯作者:
Erwin Quiring;Dan Arp;Konrad Rieck
Erwin Quiring;Dan Arp;Konrad Rieck
中科院分区:
其他
文献类型:
--
作者:
Erwin Quiring;Dan Arp;Konrad Rieck

文献摘要

被引文献

相似文献

机器学习越来越多地用于安全关键应用,如自动驾驶、人脸识别和恶意软件检测。然而,大多数学习方法在设计时并没有考虑到安全性,因此容易受到不同类型的攻击。这个问题激发了对抗性机器学习领域的研究,该领域关注攻击和防御学习方法。与此同时,另一项研究解决了一个非常相似的问题:在数字水印中,在对手存在的情况下,一个模式被嵌入到信号中。因此,该研究领域也对攻击和防御水印方法的技术进行了广泛的研究。到目前为止,这两个研究团体一直在并行工作,不知不觉地开发出类似的攻击和防御策略。这篇论文是将这些社区聚集在一起的第一次努力。为此,我们提出了针对机器学习和水印的黑箱攻击的统一符号。为了证明其有效性,我们将水印的概念应用于机器学习,反之亦然。我们表明,水印的对策可以减轻最近的模型提取攻击,类似地,强化机器学习的技术可以抵御针对水印的oracle攻击。我们进一步展示了一种基于最近来自对抗性学习的深度学习攻击的水印方案的新威胁。我们的工作提供了两个研究领域之间的概念联系,从而为提高机器学习和数字水印的安全性开辟了新的方向。
Machine learning is increasingly used in securitycritical applications, such as autonomous driving, face recognition, and malware detection. Most learning methods, however, have not been designed with security in mind and thus are vulnerable to different types of attacks. This problem has motivated the research field of adversarial machine learning that is concerned with attacking and defending learning methods. Concurrently, a separate line of research has tackled a very similar problem: In digital watermarking, a pattern is embedded in a signal in the presence of an adversary. As a consequence, this research field has also extensively studied techniques for attacking and defending watermarking methods. The two research communities have worked in parallel so far, unnoticeably developing similar attack and defense strategies. This paper is a first effort to bring these communities together. To this end, we present a unified notation of blackbox attacks against machine learning and watermarking. To demonstrate its efficacy, we apply concepts from watermarking to machine learning and vice versa. We show that countermeasures from watermarking can mitigate recent model-extraction attacks and, similarly, that techniques for hardening machine learning can fend off oracle attacks against watermarks. We further demonstrate a novel threat for watermarking schemes based on recent deep learning attacks from adversarial learning. Our work provides a conceptual link between two research fields and thereby opens novel directions for improving the security of both, machine learning and digital watermarking.