用强化学习设计新攻击,绕过信用卡欺诈检测系统
FRAUD-RLA: A new reinforcement learning adversarial attack against credit card fraud detection
- 基于强化学习优化探索与利用,降低对数据的依赖
- 在三个异构数据集上均成功绕过两种检测系统
- 适合研究欺诈防御或对抗攻击的学者参考
对抗攻击对数据驱动系统构成重大威胁,但现有研究多忽视信用卡欺诈检测这一重要场景。为此,本文提出一种新威胁模型,揭示现有攻击的局限性,并设计新型对抗攻击FRAUD-RLA,利用强化学习优化探索与利用权衡,在知识需求远低于竞品的情况下,最大化攻击者收益。实验在三个异构数据集上进行,针对两种欺诈检测系统,结果表明FRAUD-RLA在严苛威胁模型下仍具有效性。
原文摘要 · Abstract (English)
Adversarial attacks pose a significant threat to data-driven systems, and researchers have spent considerable resources studying them. Despite its economic relevance, this trend largely overlooked the issue of credit card fraud detection. To address this gap, we propose a new threat model that demonstrates the limitations of existing attacks and highlights the necessity to investigate new approaches. We then design a new adversarial attack for credit card fraud detection, employing reinforcement learning to bypass classifiers. This attack, called FRAUD-RLA, is designed to maximize the attacker's reward by optimizing the exploration-exploitation tradeoff and working with significantly less required knowledge than competitors. Our experiments, conducted on three different heterogeneous datasets and against two fraud detection systems, indicate that FRAUD-RLA is effective, even considering the severe limitations imposed by our threat model.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。