机器学习生成的可视化可能被恶意攻击误导,影响分析判断。
Adversarial Attacks on Machine Learning-Aided Visualizations
- 从可视与机器学习双视角识别攻击入口点。
- 可生成任意且欺骗性视觉结果,操纵分析决策。
- 呼吁学界尽快开展安全机制研究与防御对策。
ML4VIS 研究如何利用机器学习(ML)技术生成可视化,该领域发展迅速且具有重大社会影响。然而,与任何采用机器学习的计算流程一样,ML4VIS 方法也易受多种机器学习特有对抗攻击的影响。这些攻击可操纵可视化生成过程,诱使分析者产生误判。由于可视化与机器学习视角缺乏整合,当前文献普遍忽视这一安全问题。本文从可视化与机器学习双重视角出发,系统探究了机器学习辅助可视化中的潜在漏洞。我们首先识别出此类可视化中独有的攻击面(即攻击入口点),并以五个典型攻击案例加以说明,揭示在不同攻击能力下可能发生的多样化攻击。结果表明,攻击者可通过系统识别对机器学习推理具有影响力的输入属性,诱导生成任意且具有欺骗性的可视化内容。基于对攻击面特征及实例的观察,本文强调必须立即开展全面的安全问题研究与防御机制探索,以应对该领域的紧迫挑战。
原文摘要 · Abstract (English)
Research in ML4VIS investigates how to use machine learning (ML) techniques to generate visualizations, and the field is rapidly growing with high societal impact. However, as with any computational pipeline that employs ML processes, ML4VIS approaches are susceptible to a range of ML-specific adversarial attacks. These attacks can manipulate visualization generations, causing analysts to be tricked and their judgments to be impaired. Due to a lack of synthesis from both visualization and ML perspectives, this security aspect is largely overlooked by the current ML4VIS literature. To bridge this gap, we investigate the potential vulnerabilities of ML-aided visualizations from adversarial attacks using a holistic lens of both visualization and ML perspectives. We first identify the attack surface (i.e., attack entry points) that is unique in ML-aided visualizations. We then exemplify five different adversarial attacks. These examples highlight the range of possible attacks when considering the attack surface and multiple different adversary capabilities. Our results show that adversaries can induce various attacks, such as creating arbitrary and deceptive visualizations, by systematically identifying input attributes that are influential in ML inferences. Based on our observations of the attack surface characteristics and the attack examples, we underline the importance of comprehensive studies of security issues and defense mechanisms as a call of urgency for the ML4VIS community.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。