提出一种无需修改防御机制的组合方法,有效判断多个安全防护能否协同工作。
Combining Machine Learning Defenses without Conflicts
- 基于原理设计组合策略,无需改动原有防御模型
- 在8组已有组合中准确率达90%,30组新组合达81%
- 适用于多种防御类型,适合实际部署中快速验证组合效果
机器学习防御可保护模型免受安全、隐私和公平性风险。现实场景中需同时抵御多种风险,因此需要组合多个防御机制。但存在冲突的防御组合可能导致其中一项或多项失效,降低整体防护效果。实践者亟需一种方法来判断某组合是否有效。通过实验验证组合效率低且成本高,尤其当涉及多个防御时更为显著。理想中的组合技术应具备准确性(正确识别组合有效性)、可扩展性(支持多防御组合)、非侵入性(不修改原防御)和通用性(适用于不同防御类型)。现有方法均为临时方案,无法满足全部要求。本文提出一种系统性组合技术Def\Con,满足所有条件,在此前研究的8个组合中达到90%准确率,在本研究新评估的30个未探索组合中准确率达81%。
原文摘要 · Abstract (English)
Machine learning (ML) defenses protect against various risks to security, privacy, and fairness. Real-life models need simultaneous protection against multiple different risks which necessitates combining multiple defenses. But combining defenses with conflicting interactions in an ML model can be ineffective, incurring a significant drop in the effectiveness of one or more defenses being combined. Practitioners need a way to determine if a given combination can be effective. Experimentally identifying effective combinations can be time-consuming and expensive, particularly when multiple defenses need to be combined. We need an inexpensive, easy-to-use combination technique to identify effective combinations. Ideally, a combination technique should be (a) accurate (correctly identifies whether a combination is effective or not), (b) scalable (allows combining multiple defenses), (c) non-invasive (requires no change to the defenses being combined), and (d) general (is applicable to different types of defenses). Prior works have identified several ad-hoc techniques but none satisfy all the requirements above. We propose a principled combination technique, Def\Con, to identify effective defense combinations. Def\Con meets all requirements, achieving 90% accuracy on eight combinations explored in prior work and 81% in 30 previously unexplored combinations that we empirically evaluate in this paper.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。