Robust Artificial Intelligence Systems to Improve Security of Smartphone Users
Robust Artificial Intelligence Systems to Improve Security of Smartphone Users
批准号:
RGPIN-2019-05120
负责人:
Khan, Hassan
金额:
$2.04万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2021
资助国家:
加拿大
项目状态:
已结题
起止时间:
2021-01-01 至 2022-12-31
中文摘要
现代智能手机的广泛功能重新定义了我们的工作和娱乐方式。不幸的是,与此同时,针对个人和企业数据的威胁数量和复杂性也在增加。已经提出了几种基于人工智能的解决方案来防御这些威胁。例如,非智能手机用户未经授权使用智能手机是一种威胁,基于人工智能的持续身份验证解决方案可以解决这一问题。持续认证产品依赖于智能手机用户的设备使用行为(例如,打字或刷卡行为)。同样,基于人工智能的欺诈检测方法可以解决智能手机上恶意软件欺诈交易的威胁。虽然这些解决方案在某些情况下提高了安全性,但它们不考虑试图主动击败它们的攻击者。因此,这些解决方案可能无法提供所需的安全级别。拟议研究的长期目标是评估基于人工智能的安全解决方案针对人类对手的安全特性,这些对手将承担不同的攻击能力,对现有系统提出改进建议,使它们能够抵御人类对手。确定向用户传达这些方法的属性的最有效方法,以便他们可以选择最适合他们的配置,同时最大限度地减少由于误解和错误配置而导致的事件。这项研究的近期目标是加强两种基于人工智能的系统的安全性,这两种系统目前被用于提高移动用户的安全性,连续身份验证系统和设备指纹,以抵御来自人类对手的基于模仿的攻击(“模仿攻击”)。激动人心的时代即将到来:企业越来越多地采用基于人工智能的连续身份验证解决方案,如三星BioCatch和IBM Trusteer。金融机构正在广泛使用基于人工智能的欺诈检测方法来标记潜在的欺诈交易。虽然这些努力带来了巨大的希望,但仔细评估这些系统提供的安全性以应对足智多谋的对手是至关重要的。我们的研究将确保安全从业者和产品设计师不仅意识到基于人工智能的安全系统目前的局限性,而且还意识到他们可以采取的措施,使这些解决方案对活跃的对手更加强大。最后,通过向最终用户提供控制,我们将解决这些系统中经常被忽视的人为方面。
英文摘要
The wide-ranging capabilities of modern smartphones have redefined how we work and entertain ourselves. Unfortunately, this is accompanied with an increase in the number and sophistication of threats to personal and corporate data. Several AI-based solutions have been put forth that provide defences against these threats. For instance, unauthorized usage of smartphones by non-owners is a threat that is addressed by AI-based continuous authentication solutions. Continuous authentication products rely on the device usage behaviour of smartphone owners (e.g., typing or swiping behaviour). Similarly, AI-based fraud detection methods address the threat of fraudulent transactions by malware on smartphones. While these solutions improve security under some circumstances, they do not consider attackers that attempt to actively defeat them. As a result, these solutions may not provide the desired level of security. The long-term goal of the proposed research is to evaluate the security properties of AI-based security solutions against human adversaries who will assume different attack capabilities, propose improvements to the existing systems so that they are resilient against human adversaries, and the identification of the most effective way to communicate properties of these methods to users so that they can choose the configuration that works best for them while minimizing incidents due to miscomprehension and misconfiguration. The near-term goal of this research is to bolster the security of two AI-based systems that are currently being used to improve the security of mobile users, continuous authentication systems and device fingerprinting, against imitation-based attacks ("mimicry attacks") from human adversaries. Exciting times are ahead: enterprises are increasingly adopting AI-based continuous authentication solutions like Samsung BioCatch and IBM Trusteer. Financial institutions are widely using AI-based fraud detection methods to flag potentially fraudulent transactions. While these efforts hold great promise, it is critical to carefully evaluate the security offered by these systems against resourceful adversaries. Our research will ensure that security practitioners and product designers are not only aware of the present limitations of the AI-based security systems but also aware of the measures they can take to make these solutions more robust against active adversaries. Finally, by providing controls to the end users, we will address the often neglected human side of these systems.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Robust Artificial Intelligence Systems to Improve Security of Smartphone Users
-
批准号:RGPIN-2019-05120
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2022
-
负责人:Khan, Hassan
-
依托单位:
Robust Artificial Intelligence Systems to Improve Security of Smartphone Users
-
批准号:RGPIN-2019-05120
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2020
-
负责人:Khan, Hassan
-
依托单位:
Robust Artificial Intelligence Systems to Improve Security of Smartphone Users
-
批准号:DGECR-2019-00208
-
项目类别:Discovery Launch Supplement
-
资助金额:$0.91万
-
财政年份:2019
-
负责人:Khan, Hassan
-
依托单位:
Robust Artificial Intelligence Systems to Improve Security of Smartphone Users
-
批准号:RGPIN-2019-05120
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2019
-
负责人:Khan, Hassan
-
依托单位:
海外基金