TA3系统通过人机协同实现对抗攻击测试可视化。
TA3: Testing Against Adversarial Attacks on Machine Learning Models
- 引入人机协同机制,支持人工驱动的对抗攻击模拟。
- 聚焦决策树模型,基于单像素攻击方法开展测试验证。
- 适合安全评估人员和机器学习开发者使用。
对抗攻击是机器学习模型在诸多应用中部署时的主要威胁。对机器学习模型进行对抗攻击测试已成为评估和改进模型的重要步骤。本文报告了交互式测试系统TA3的设计与开发,该系统旨在支持对抗攻击测试(TA3)的工作流程。具体而言,通过人机协同(HITL)机制,实现人工引导的攻击模拟和可视化辅助的攻击影响评估。当前版本的TA3专注于基于单像素攻击方法的决策树模型对抗测试,展示了人机协同在机器学习测试中的重要性,并证明其在其他类型模型及攻击方法中的潜在应用价值。
原文摘要 · Abstract (English)
Adversarial attacks are major threats to the deployment of machine learning (ML) models in many applications. Testing ML models against such attacks is becoming an essential step for evaluating and improving ML models. In this paper, we report the design and development of an interactive system for aiding the workflow of Testing Against Adversarial Attacks (TA3). In particular, with TA3, human-in-the-loop (HITL) enables human-steered attack simulation and visualization-assisted attack impact evaluation. While the current version of TA3 focuses on testing decision tree models against adversarial attacks based on the One Pixel Attack Method, it demonstrates the importance of HITL in ML testing and the potential application of HITL to the ML testing workflows for other types of ML models and other types of adversarial attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。