Mental Models of Adversarial Machine Learning
arXiv:2105.03726
Abstract
Although machine learning is widely used in practice, little is known about practitioners' understanding of potential security challenges. In this work, we close this substantial gap and contribute a qualitative study focusing on developers' mental models of the machine learning pipeline and potentially vulnerable components. Similar studies have helped in other security fields to discover root causes or improve risk communication. Our study reveals two \facets of practitioners' mental models of machine learning security. Firstly, practitioners often confuse machine learning security with threats and defences that are not directly related to machine learning. Secondly, in contrast to most academic research, our participants perceive security of machine learning as not solely related to individual models, but rather in the context of entire workflows that consist of multiple components. Jointly with our additional findings, these two facets provide a foundation to substantiate mental models for machine learning security and have implications for the integration of adversarial machine learning into corporate workflows, \new{decreasing practitioners' reported uncertainty}, and appropriate regulatory frameworks for machine learning security.
accepted at SOUPS 2022
References in corpus (12)
- Wild Patterns: Ten Years After the Rise of Adversarial Machine Learning
- Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning
- What Do We Want From Explainable Artificial Intelligence (XAI)? -- A Stakeholder Perspective on XAI and a Conceptual Model Guiding Interdisciplinary XAI Research
- Motivating the Rules of the Game for Adversarial Example Research
- AttriGuard: A Practical Defense Against Attribute Inference Attacks via Adversarial Machine Learning
- Adversarial Machine Learning -- Industry Perspectives
- Towards Reverse-Engineering Black-Box Neural Networks
- On the Robustness of Convolutional Neural Networks to Internal Architecture and Weight Perturbations
- Bad Global Minima Exist and SGD Can Reach Them
- Adversarial Reprogramming of Neural Networks
- Security and Machine Learning in the Real World
- Understanding Mental Models of AI through Player-AI Interaction