On the Robustness of Domain Constraints

On the Robustness of Domain Constraints
复制标题

DOI:
10.1145/3460120.3484570
复制
发表时间:
2021-05
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Ryan Sheatsley;Blaine Hoak;Eric Pauley;Yohan Beugin;Mike Weisman;P. Mcdaniel
Ryan Sheatsley;Blaine Hoak;Eric Pauley;Yohan Beugin;Mike Weisman;P. Mcdaniel
中科院分区:
其他
文献类型:
--
作者:
Ryan Sheatsley;Blaine Hoak;Eric Pauley;Yohan Beugin;Mike Weisman;P. Mcdaniel

文献摘要

相似文献

机器学习很容易受到对抗性示例的影响,即设计用于导致模型表现不佳的输入。然而,目前尚不清楚对抗性示例是否代表建模领域中的实际输入。网络和网络钓鱼等不同的领域都有领域约束——攻击者必须满足的特征之间的复杂关系才能实现攻击(除了任何攻击者特定的目标之外)。在本文中,我们探讨了领域约束如何限制对抗能力,以及对手如何调整他们的策略来创建现实的(约束兼容的)示例。在此,我们开发了从数据中学习领域约束的技术,并展示了如何将学习到的约束集成到对抗性制作过程中。我们评估了我们的方法在网络入侵和网络钓鱼数据集中的有效性,并发现:(1)由最先进的制作算法产生的多达82%的对抗示例违反域约束,(2)域约束对对抗示例具有鲁棒性;执行约束可以使模型精度提高34%。我们不仅观察到对手必须改变输入以满足域约束,而且这些约束使得生成有效的对抗性示例更具挑战性。
Machine learning is vulnerable to adversarial examples--inputs designed to cause models to perform poorly. However, it is unclear if adversarial examples represent realistic inputs in the modeled domains. Diverse domains such as networks and phishing have domain constraints--complex relationships between features that an adversary must satisfy for an attack to be realized (in addition to any adversary-specific goals). In this paper, we explore how domain constraints limit adversarial capabilities and how adversaries can adapt their strategies to create realistic (constraint-compliant) examples. In this, we develop techniques to learn domain constraints from data, and show how the learned constraints can be integrated into the adversarial crafting process. We evaluate the efficacy of our approach in network intrusion and phishing datasets and find: (1) up to 82% of adversarial examples produced by state-of-the-art crafting algorithms violate domain constraints, (2) domain constraints are robust to adversarial examples; enforcing constraints yields an increase in model accuracy by up to 34%. We observe not only that adversaries must alter inputs to satisfy domain constraints, but that these constraints make the generation of valid adversarial examples far more challenging.