Security Evaluation of Pattern Classifiers under Attack

Security Evaluation of Pattern Classifiers under Attack
复制标题

DOI:
10.1109/tkde.2013.57
复制
发表时间:
2014-04-01
影响因子:
8.9
通讯作者:
Roli, Fabio
Roli, Fabio
中科院分区:
计算机科学2区
文献类型:
--
作者:
Biggio, Battista;Fumera, Giorgio;Roli, Fabio

文献摘要

被引文献

相似文献

模式分类系统通常用于对抗应用程序中,例如生物识别身份验证,网络入侵检测和垃圾邮件过滤,其中人类可以故意操纵数据以破坏其操作。由于没有通过经典设计方法考虑这种对抗性方案,因此模式分类系统可能会表现出脆弱性,其剥削可能会严重影响其性能,因此限制了其实际实用性。因此,将模式分类理论和设计方法扩展到对抗设置是一个新颖且非常相关的研究方向,尚未以系统的方式追求。在本文中,我们解决了主要的开放问题之一:在设计阶段进行评估模式分类器的安全性,即,在操作过程中可能引起的潜在攻击下的性能下降。我们提出了一个对分类器安全性经验评估的框架,该框架将文献中提出的主要思想形式化和推广,并举例说明了其在三个实际应用中的使用。报告的结果表明,安全评估可以更完整地了解分类器在对抗环境中的行为,并带来更好的设计选择。
Pattern classification systems are commonly used in adversarial applications, like biometric authentication, network intrusion detection, and spam filtering, in which data can be purposely manipulated by humans to undermine their operation. As this adversarial scenario is not taken into account by classical design methods, pattern classification systems may exhibit vulnerabilities, whose exploitation may severely affect their performance, and consequently limit their practical utility. Extending pattern classification theory and design methods to adversarial settings is thus a novel and very relevant research direction, which has not yet been pursued in a systematic way. In this paper, we address one of the main open issues: evaluating at design phase the security of pattern classifiers, namely, the performance degradation under potential attacks they may incur during operation. We propose a framework for empirical evaluation of classifier security that formalizes and generalizes the main ideas proposed in the literature, and give examples of its use in three real applications. Reported results show that security evaluation can provide a more complete understanding of the classifier's behavior in adversarial environments, and lead to better design choices.