Security and Privacy for Artificial Intelligence: Opportunities and Challenges
arXiv:2102.04661
Abstract
The increased adoption of Artificial Intelligence (AI) presents an opportunity to solve many socio-economic and environmental challenges; however, this cannot happen without securing AI-enabled technologies. In recent years, most AI models are vulnerable to advanced and sophisticated hacking techniques. This challenge has motivated concerted research efforts into adversarial AI, with the aim of developing robust machine and deep learning models that are resilient to different types of adversarial scenarios. In this paper, we present a holistic cyber security review that demonstrates adversarial attacks against AI applications, including aspects such as adversarial knowledge and capabilities, as well as existing methods for generating adversarial examples and existing cyber defence models. We explain mathematical AI models, especially new variants of reinforcement and federated learning, to demonstrate how attack vectors would exploit vulnerabilities of AI models. We also propose a systematic framework for demonstrating attack techniques against AI applications and reviewed several cyber defences that would protect AI applications against those attacks. We also highlight the importance of understanding the adversarial goals and their capabilities, especially the recent attacks against industry applications, to develop adaptive defences that assess to secure AI applications. Finally, we describe the main challenges and future research directions in the domain of security and privacy of AI technologies.
References in corpus (18)
- Distilling the Knowledge in a Neural Network
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- Federated Optimization: Distributed Machine Learning for On-Device Intelligence
- Poisoning Attacks against Support Vector Machines
- Towards Deep Neural Network Architectures Robust to Adversarial Examples
- The Space of Transferable Adversarial Examples
- Security Evaluation of Pattern Classifiers under Attack
- Generating Adversarial Malware Examples for Black-Box Attacks Based on GAN
- CryptoDL: Deep Neural Networks over Encrypted Data
- Adversarial Transformation Networks: Learning to Generate Adversarial Examples
- Towards Crafting Text Adversarial Samples
- Generative Poisoning Attack Method Against Neural Networks
- Crypto-Nets: Neural Networks over Encrypted Data
- UPSET and ANGRI : Breaking High Performance Image Classifiers
- Security Analysis of Online Centroid Anomaly Detection
- Adversarial Examples in Modern Machine Learning: A Review
- Feature Squeezing Mitigates and Detects Carlini/Wagner Adversarial Examples
- Robustness to Adversarial Examples through an Ensemble of Specialists