发现信用卡欺诈检测模型易受对抗攻击,且攻击可跨模型转移。
Foe for Fraud: Transferable Adversarial Attacks in Credit Card Fraud Detection
- 用基于梯度的方法在信用卡交易表数据上生成对抗样本。
- 黑盒与白盒攻击下,模型误判率显著上升,攻击效果持续存在。
- 结果提示金融科技从业者需重视模型安全防御。
信用卡欺诈检测(CCFD)是机器学习在金融领域的关键应用,准确识别欺诈交易对减少财务损失至关重要。尽管深度学习在计算机视觉等领域已广泛研究对抗攻击,但针对基于表格数据的CCFD模型的对抗性威胁仍鲜有探索。本文提出一个全面框架,系统研究CCFD模型在不同场景下对对抗扰动的鲁棒性。具体地,在黑盒与白盒设置中,将基于梯度的攻击方法应用于信用卡交易表数据。实验结果表明,表格式数据同样易受细微扰动影响,凸显了金融行业对机器学习模型安全性的关注必要性。进一步实验验证,由基于梯度的攻击生成的对抗样本可有效转移到非梯度模型,攻击依然有效,强调了构建强健防御机制的紧迫性。
原文摘要 · Abstract (English)
Credit card fraud detection (CCFD) is a critical application of Machine Learning (ML) in the financial sector, where accurately identifying fraudulent transactions is essential for mitigating financial losses. ML models have demonstrated their effectiveness in fraud detection task, in particular with the tabular dataset. While adversarial attacks have been extensively studied in computer vision and deep learning, their impacts on the ML models, particularly those trained on CCFD tabular datasets, remains largely unexplored. These latent vulnerabilities pose significant threats to the security and stability of the financial industry, especially in high-value transactions where losses could be substantial. To address this gap, in this paper, we present a holistic framework that investigate the robustness of CCFD ML model against adversarial perturbations under different circumstances. Specifically, the gradient-based attack methods are incorporated into the tabular credit card transaction data in both black- and white-box adversarial attacks settings. Our findings confirm that tabular data is also susceptible to subtle perturbations, highlighting the need for heightened awareness among financial technology practitioners regarding ML model security and trustworthiness. Furthermore, the experiments by transferring adversarial samples from gradient-based attack method to non-gradient-based models also verify our findings. Our results demonstrate that such attacks remain effective, emphasizing the necessity of developing robust defenses for CCFD algorithms.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。