Enhancing robustness of machine learning systems via data transformations

Enhancing robustness of machine learning systems via data transformations
复制标题

DOI:
10.1109/ciss.2018.8362326
复制
发表时间:
2017-04
期刊:
2018 52nd Annual Conference on Information Sciences and Systems (CISS)
影响因子:
--
通讯作者:
A. Bhagoji;Daniel Cullina;Chawin Sitawarin;Prateek Mittal
A. Bhagoji;Daniel Cullina;Chawin Sitawarin;Prateek Mittal
中科院分区:
其他
文献类型:
--
作者:
A. Bhagoji;Daniel Cullina;Chawin Sitawarin;Prateek Mittal

文献摘要

被引文献

相似文献

我们建议使用数据转换来防御机器学习分类器的规避攻击。我们提出并研究了整合各种数据转换的策略,包括通过主成分分析进行降维,以增强机器学习的弹性,针对分类和训练阶段。我们使用多个真实世界数据集凭经验评估并证明了数据线性变换作为防御规避攻击的防御机制的可行性。我们的主要发现是,这种防御措施 (i) 能够有效抵御文献中最著名的规避攻击,从而使了解成功攻击防御知识的白盒对手所需的资源增加两倍,(ii) 适用于一系列 ML 分类器,包括支持向量机和深度神经网络,以及 (iii) 可推广到多个应用领域,包括图像分类和人类活动分类。
We propose the use of data transformations as a defense against evasion attacks on ML classifiers. We present and investigate strategies for incorporating a variety of data transformations including dimensionality reduction via Principal Component Analysis to enhance the resilience of machine learning, targeting both the classification and the training phase. We empirically evaluate and demonstrate the feasibility of linear transformations of data as a defense mechanism against evasion attacks using multiple real-world datasets. Our key findings are that the defense is (i) effective against the best known evasion attacks from the literature, resulting in a two-fold increase in the resources required by a white-box adversary with knowledge of the defense for a successful attack, (ii) applicable across a range of ML classifiers, including Support Vector Machines and Deep Neural Networks, and (iii) generalizable to multiple application domains, including image classification and human activity classification.