The Many Faces of Adversarial Machine Learning

The Many Faces of Adversarial Machine Learning
复制标题

DOI:
10.1609/aaai.v37i13.26796
复制
发表时间:
2023-06
期刊:
--
影响因子:
--
通讯作者:
Yevgeniy Vorobeychik
Yevgeniy Vorobeychik
中科院分区:
其他
文献类型:
--
作者:
Yevgeniy Vorobeychik

文献摘要

被引文献

相似文献

对抗性机器学习(AML)研究关注机器学习模型和算法对恶意篡改的鲁棒性。AML起源于机器学习和网络安全之间的交叉点,具有更广泛的研究吸引力,将传统的安全概念扩展到包括计算机视觉,自然语言处理和网络科学的应用。此外,策略分类、算法追索和反事实解释的问题与AML具有基本相同的核心数学结构,尽管动机不同。我简要介绍了AML中的核心问题,然后讨论了安全驱动的AML领域,以及上述与安全无关的问题。这些共同跨越了许多重要的人工智能子学科,但都可以广泛地被视为与值得信赖的人工智能有关。我的目标是澄清两者之间的技术联系,以及实质性的差异,为未来的研究方向提出建议。
Adversarial machine learning (AML) research is concerned with robustness of machine learning models and algorithms to malicious tampering. Originating at the intersection between machine learning and cybersecurity, AML has come to have broader research appeal, stretching traditional notions of security to include applications of computer vision, natural language processing, and network science. In addition, the problems of strategic classification, algorithmic recourse, and counterfactual explanations have essentially the same core mathematical structure as AML, despite distinct motivations. I give a simplified overview of the central problems in AML, and then discuss both the security-motivated AML domains, and the problems above unrelated to security. These together span a number of important AI subdisciplines, but can all broadly be viewed as concerned with trustworthy AI. My goal is to clarify both the technical connections among these, as well as the substantive differences, suggesting directions for future research.