Machine Learning Security in Industry: A Quantitative Survey
arXiv:2207.05164 · doi:10.1109/TIFS.2023.3251842
Abstract
Despite the large body of academic work on machine learning security, little is known about the occurrence of attacks on machine learning systems in the wild. In this paper, we report on a quantitative study with 139 industrial practitioners. We analyze attack occurrence and concern and evaluate statistical hypotheses on factors influencing threat perception and exposure. Our results shed light on real-world attacks on deployed machine learning. On the organizational level, while we find no predictors for threat exposure in our sample, the amount of implement defenses depends on exposure to threats or expected likelihood to become a target. We also provide a detailed analysis of practitioners' replies on the relevance of individual machine learning attacks, unveiling complex concerns like unreliable decision making, business information leakage, and bias introduction into models. Finally, we find that on the individual level, prior knowledge about machine learning security influences threat perception. Our work paves the way for more research about adversarial machine learning in practice, but yields also insights for regulation and auditing.
Accepted at TIFS, version with more detailed appendix containing more detailed statistical results. 17 pages, 6 tables and 4 figures
References in corpus (4)
- Explainable Artificial Intelligence: Understanding, Visualizing and Interpreting Deep Learning Models
- Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning
- Wild Patterns Reloaded: A Survey of Machine Learning Security against Training Data Poisoning
- Beyond Expertise and Roles: A Framework to Characterize the Stakeholders of Interpretable Machine Learning and their Needs
Cited by in corpus (4)
- Wild Patterns Reloaded: A Survey of Machine Learning Security against Training Data Poisoning
- Machine Learning (In) Security: A Stream of Problems
- SecMLOps: A Comprehensive Framework for Integrating Security Throughout the MLOps Lifecycle
- Footprints of Data in a Classifier: Understanding the Privacy Risks and Solution Strategies