arXiv:2412.08366cs.LG2024-12

保险领域模型易受后门攻击,少量恶意数据即可失效。

Backdoor attacks on DNN and GBDT -- A Case Study from the insurance domain

  • 在保险数据中注入特定模式样本进行后门攻击
  • 仅需少量恶意数据就可成功操纵模型预测结果
  • 适用于关注模型安全的保险科技从业者

机器学习(ML)将在未来保险业务中扮演重要角色,但其面临被攻击和篡改的风险。本文评估了梯度提升决策树(GBDT)与深度神经网络(DNN)在保险场景下的鲁棒性。在两个来自保险领域的表格数据集上训练了两组GBDT和两组DNN模型,分别执行理赔预测(回归)和欺诈检测(二分类)。现有研究多基于同质数据,对异构表格数据的洞察较少。通过在训练数据中加入含特定模式的恶意样本实施后门攻击,结果显示该攻击在某一数据集上的模型上效果显著,而在另一数据集上则表现不佳。尽管真实场景存在多重障碍,但攻击仅需极少样本即可生效,提示应重视此类风险。

原文摘要 · Abstract (English)

Machine learning (ML) will likely play a large role in many processes in the future, also for insurance companies. However, ML models are at risk of being attacked and manipulated. In this work, the robustness of Gradient Boosted Decision Tree (GBDT) models and Deep Neural Networks (DNN) within an insurance context will be evaluated. Therefore, two GBDT models and two DNNs are trained on two different tabular datasets from an insurance context. Past research in this domain mainly used homogenous data and there are comparably few insights regarding heterogenous tabular data. The ML tasks performed on the datasets are claim prediction (regression) and fraud detection (binary classification). For the backdoor attacks different samples containing a specific pattern were crafted and added to the training data. It is shown, that this type of attack can be highly successful, even with a few added samples. The backdoor attacks worked well on the models trained on one dataset but poorly on the models trained on the other. In real-world scenarios the attacker will have to face several obstacles but as attacks can work with very few added samples this risk should be evaluated.

后门攻击保险科技模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。