On the Security Risks of AutoML

On the Security Risks of AutoML
复制标题

DOI:
--
复制
发表时间:
2021-10
期刊:
--
影响因子:
--
通讯作者:
Ren Pang;Zhaohan Xi;S. Ji;Xiapu Luo;Ting Wang
Ren Pang;Zhaohan Xi;S. Ji;Xiapu Luo;Ting Wang
中科院分区:
其他
文献类型:
--
作者:
Ren Pang;Zhaohan Xi;S. Ji;Xiapu Luo;Ting Wang

文献摘要

被引文献

相似文献

神经架构搜索 (NAS) 代表了一种新兴的机器学习 (ML) 范式,可自动搜索针对给定任务定制的模型,这极大地简化了 ML 系统的开发,并推动了 ML 民主化的趋势。然而,人们对 NAS 带来的潜在安全风险知之甚少,鉴于 NAS 生成的模型在关键领域的使用越来越多,这一点令人担忧。这项工作代表了缩小差距的坚实的第一步。通过对 10 种流行的 NAS 方法进行广泛的实证研究,我们表明,与手动设计的模型相比,NAS 生成的模型往往更容易受到各种恶意攻击(例如,对抗性规避、模型中毒和功能窃取)。此外,通过经验和分析证据,我们为此类现象提供了可能的解释:考虑到令人望而却步的搜索空间和训练成本,大多数 NAS 方法都倾向于在早期训练阶段快速收敛的模型;这种偏好导致与攻击漏洞相关的架构属性(例如,高损失平滑度和低梯度方差)。我们的研究结果不仅揭示了模型特征与攻击漏洞之间的关系,还表明了不同攻击背后的内在联系。最后,我们讨论了减轻这些缺点的潜在补救措施,包括增加单元深度和抑制跳跃连接,这导致了几个有前途的研究方向。
Neural Architecture Search (NAS) represents an emerging machine learning (ML) paradigm that automatically searches for models tailored to given tasks, which greatly simplifies the development of ML systems and propels the trend of ML democratization. Yet, little is known about the potential security risks incurred by NAS, which is concerning given the increasing use of NAS-generated models in critical domains. This work represents a solid initial step towards bridging the gap. Through an extensive empirical study of 10 popular NAS methods, we show that compared with their manually designed counterparts, NAS-generated models tend to suffer greater vulnerability to various malicious attacks (e.g., adversarial evasion, model poisoning, and functionality stealing). Further, with both empirical and analytical evidence, we provide possible explanations for such phenomena: given the prohibitive search space and training cost, most NAS methods favor models that converge fast at early training stages; this preference results in architectural properties associated with attack vulnerability (e.g., high loss smoothness and low gradient variance). Our findings not only reveal the relationships between model characteristics and attack vulnerability but also suggest the inherent connections underlying different attacks. Finally, we discuss potential remedies to mitigate such drawbacks, including increasing cell depth and suppressing skip connects, which lead to several promising research directions.