Data Driven Exploratory Attacks on Black Box Classifiers in Adversarial Domains
arXiv:1703.07909 · doi:10.1016/j.neucom.2018.02.007
Abstract
While modern day web applications aim to create impact at the civilization level, they have become vulnerable to adversarial activity, where the next cyber-attack can take any shape and can originate from anywhere. The increasing scale and sophistication of attacks, has prompted the need for a data driven solution, with machine learning forming the core of many cybersecurity systems. Machine learning was not designed with security in mind, and the essential assumption of stationarity, requiring that the training and testing data follow similar distributions, is violated in an adversarial domain. In this paper, an adversary's view point of a classification based system, is presented. Based on a formal adversarial model, the Seed-Explore-Exploit framework is presented, for simulating the generation of data driven and reverse engineering attacks on classifiers. Experimental evaluation, on 10 real world datasets and using the Google Cloud Prediction Platform, demonstrates the innate vulnerability of classifiers and the ease with which evasion can be carried out, without any explicit information about the classifier type, the training data or the application domain. The proposed framework, algorithms and empirical evaluation, serve as a white hat analysis of the vulnerabilities, and aim to foster the development of secure machine learning frameworks.
References in corpus (6)
- Security Evaluation of Pattern Classifiers under Attack
- Learning under Concept Drift: an Overview
- Support Vector Machines under Adversarial Label Contamination
- An Evasion and Counter-Evasion Study in Malicious Websites Detection
- Near-Optimal Evasion of Convex-Inducing Classifiers
- Application Layer Intrusion Detection with Combination of Explicit-Rule- Based and Machine Learning Algorithms and Deployment in Cyber- Defence Program
Cited by in corpus (11)
- Adversarial Frontier Stitching for Remote Neural Network Watermarking
- Modeling Realistic Adversarial Attacks against Network Intrusion Detection Systems
- I Know What You Trained Last Summer: A Survey on Stealing Machine Learning Models and Defences
- Secure and Trustworthy Artificial Intelligence-Extended Reality (AI-XR) for Metaverses
- POBA-GA: Perturbation Optimized Black-Box Adversarial Attacks via Genetic Algorithm
- Handling Adversarial Concept Drift in Streaming Data
- A Survey of Game Theoretic Approaches for Adversarial Machine Learning in Cybersecurity Tasks
- Curls & Whey: Boosting Black-Box Adversarial Attacks
- A Dynamic-Adversarial Mining Approach to the Security of Machine Learning
- Exploring Adversarial Examples for Efficient Active Learning in Machine Learning Classifiers
- Adversarial Attacks for Multi-view Deep Models