测试发现AI取证工具易受对抗攻击,无法可靠识别敏感内容。
Exploring the Robustness of AI-Driven Tools in Digital Forensics: A Preliminary Study
- 用200张图像和3次聊天数据测试两款AI取证工具
- 部分色情图像未被识别为裸露,深度伪造图与真人难分
- 适合关注AI安全性的数字取证研究人员参考
当前许多数字取证工具利用人工智能(AI)自动将数据分类为特定类别(如毒品、武器、裸露)。然而,这引发对AI算法抗对抗攻击能力的担忧。有人可能通过篡改内容使AI无法识别违规信息,从而规避检测,构成反取证攻击。为此,我们对两款主流工具进行了初步测试:Magnet AI(用于Magnet Axiom)和Excire Photo AI(用于X-Ways Forensics)。测试使用约200张图像,另100张通过3次聊天传递,涉及色情与青少年裸露、毒品及武器。同时加载由AI生成的深度伪造图像(伪造真实人物),观察其分类表现。结果表明,现有AI模型鲁棒性不足:部分色情图像未被标记为裸露,部分深度伪造图像被误判为真实人物,而人类可轻易区分。基于此,结合最新研究,本文提出改进取证工具中AI应用与抗干扰能力的建议。
原文摘要 · Abstract (English)
Nowadays, many tools are used to facilitate forensic tasks about data extraction and data analysis. In particular, some tools leverage Artificial Intelligence (AI) to automatically label examined data into specific categories (\ie, drugs, weapons, nudity). However, this raises a serious concern about the robustness of the employed AI algorithms against adversarial attacks. Indeed, some people may need to hide specific data to AI-based digital forensics tools, thus manipulating the content so that the AI system does not recognize the offensive/prohibited content and marks it at as suspicious to the analyst. This could be seen as an anti-forensics attack scenario. For this reason, we analyzed two of the most important forensics tools employing AI for data classification: Magnet AI, used by Magnet Axiom, and Excire Photo AI, used by X-Ways Forensics. We made preliminary tests using about $200$ images, other $100$ sent in $3$ chats about pornography and teenage nudity, drugs and weapons to understand how the tools label them. Moreover, we loaded some deepfake images (images generated by AI forging real ones) of some actors to understand if they would be classified in the same category as the original images. From our preliminary study, we saw that the AI algorithm is not robust enough, as we expected since these topics are still open research problems. For example, some sexual images were not categorized as nudity, and some deepfakes were categorized as the same real person, while the human eye can see the clear nudity image or catch the difference between the deepfakes. Building on these results and other state-of-the-art works, we provide some suggestions for improving how digital forensics analysis tool leverage AI and their robustness against adversarial attacks or different scenarios than the trained one.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。