Rethinking Image-Scaling Attacks: The Interplay Between Vulnerabilities in Machine Learning Systems
arXiv:2104.08690
Abstract
As real-world images come in varying sizes, the machine learning model is part of a larger system that includes an upstream image scaling algorithm. In this paper, we investigate the interplay between vulnerabilities of the image scaling procedure and machine learning models in the decision-based black-box setting. We propose a novel sampling strategy to make a black-box attack exploit vulnerabilities in scaling algorithms, scaling defenses, and the final machine learning model in an end-to-end manner. Based on this scaling-aware attack, we reveal that most existing scaling defenses are ineffective under threat from downstream models. Moreover, we empirically observe that standard black-box attacks can significantly improve their performance by exploiting the vulnerable scaling procedure. We further demonstrate this problem on a commercial Image Analysis API with decision-based black-box attacks.
Accepted by Proceedings of the 39th International Conference on Machine Learning
References in corpus (7)
- PyTorch: An Imperative Style, High-Performance Deep Learning Library
- Certified Adversarial Robustness via Randomized Smoothing
- On Evaluating Adversarial Robustness
- LowKey: Leveraging Adversarial Attacks to Protect Social Media Users from Facial Recognition
- Security and Machine Learning in the Real World
- Manipulating SGD with Data Ordering Attacks
- On the Exploitability of Audio Machine Learning Pipelines to Surreptitious Adversarial Examples