arXiv:2502.05637cs.CRcs.AI2025-02被引 1

揭示AI系统在对抗攻击下的脆弱性及防御难题

Adversarial Machine Learning: Attacks, Defenses, and Open Challenges

  • 分析输入扰动与训练数据污染两类攻击
  • 提出数学严谨的防御机制框架
  • 指出鲁棒性认证、扩展性等关键挑战

对抗机器学习(AML)研究人工智能系统在对手操纵输入或训练数据时的漏洞。本文全面分析了逃避攻击与投毒攻击,以数学方法形式化防御机制,并讨论了在动态威胁模型下实现鲁棒解决方案的挑战。此外,文章还指出了认证鲁棒性、可扩展性以及实际部署中的开放问题。

原文摘要 · Abstract (English)

Adversarial Machine Learning (AML) addresses vulnerabilities in AI systems where adversaries manipulate inputs or training data to degrade performance. This article provides a comprehensive analysis of evasion and poisoning attacks, formalizes defense mechanisms with mathematical rigor, and discusses the challenges of implementing robust solutions in adaptive threat models. Additionally, it highlights open challenges in certified robustness, scalability, and real-world deployment.

对抗攻击模型安全防御机制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。