Security for Machine Learning-based Systems: Attacks and Challenges during Training and Inference
arXiv:1811.01463 · doi:10.1109/FIT.2018.00064
Abstract
The exponential increase in dependencies between the cyber and physical world leads to an enormous amount of data which must be efficiently processed and stored. Therefore, computing paradigms are evolving towards machine learning (ML)-based systems because of their ability to efficiently and accurately process the enormous amount of data. Although ML-based solutions address the efficient computing requirements of big data, they introduce (new) security vulnerabilities into the systems, which cannot be addressed by traditional monitoring-based security measures. Therefore, this paper first presents a brief overview of various security threats in machine learning, their respective threat models and associated research challenges to develop robust security measures. To illustrate the security vulnerabilities of ML during training, inferencing and hardware implementation, we demonstrate some key security threats on ML using LeNet and VGGNet for MNIST and German Traffic Sign Recognition Benchmarks (GTSRB), respectively. Moreover, based on the security analysis of ML-training, we also propose an attack that has a very less impact on the inference accuracy. Towards the end, we highlight the associated research challenges in developing security measures and provide a brief overview of the techniques used to mitigate such security threats.
References in corpus (6)
- BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain
- CryptoDL: Deep Neural Networks over Encrypted Data
- SafetyNets: Verifiable Execution of Deep Neural Networks on an Untrusted Cloud
- DeepSafe: A Data-driven Approach for Checking Adversarial Robustness in Neural Networks
- DeepAPT: Nation-State APT Attribution Using End-to-End Deep Neural Networks
- Modular Learning Component Attacks: Today's Reality, Tomorrow's Challenge
Cited by in corpus (7)
- Hardware and Software Optimizations for Accelerating Deep Neural Networks: Survey of Current Trends, Challenges, and the Road Ahead
- Robust Machine Learning Systems: Challenges, Current Trends, Perspectives, and the Road Ahead
- Machine Learning for Security in Vehicular Networks: A Comprehensive Survey
- QuSecNets: Quantization-based Defense Mechanism for Securing Deep Neural Network against Adversarial Attacks
- TrISec: Training Data-Unaware Imperceptible Security Attacks on Deep Neural Networks
- Adversarial Security Attacks and Perturbations on Machine Learning and Deep Learning Methods
- Adversarial Text Rewriting for Text-aware Recommender Systems