arXiv:2508.17405cs.LGcs.CR2025-08被引 1

首个自动化框架,全面评估机器学习系统的对抗攻击风险。

FRAME : Comprehensive Risk Assessment Framework for Adversarial Machine Learning Threats

  • 从部署环境、攻击特性、已有研究三方面量化风险
  • 在6个真实系统中验证,准确率高且专家分析一致
  • 适合无对抗机器学习专长的系统所有者使用

机器学习系统广泛应用,催生了对抗机器学习(AML)威胁,亟需全面的风险评估。现有框架多聚焦传统网络安全,难以应对AML独特挑战;现有AML评估侧重技术鲁棒性,忽略实际部署环境、系统依赖和攻击可行性。已有方案多限于特定领域,难以跨系统应用。为此,我们提出FRAME——首个面向多样化机器学习系统的综合自动化风险评估框架。它通过系统评估目标系统的部署环境、多样AML技术特征及前期研究实证,实现风险量化,并引入可行性评分机制与LLM定制化能力。我们构建了一个结构化的AML攻击数据集,支持上下文感知评估。从工程角度看,结果可直接用于系统所有者决策,仅需其了解自身系统技术细节,无需掌握AML专业知识。我们在六个真实应用中验证框架,结果显示极高准确率,且与专家分析高度一致。FRAME帮助组织优先处理风险,支撑真实环境中安全部署AI。

原文摘要 · Abstract (English)

The widespread adoption of machine learning (ML) systems increased attention to their security and emergence of adversarial machine learning (AML) techniques that exploit fundamental vulnerabilities in ML systems, creating an urgent need for comprehensive risk assessment for ML-based systems. While traditional risk assessment frameworks evaluate conventional cybersecurity risks, they lack ability to address unique challenges posed by AML threats. Existing AML threat evaluation approaches focus primarily on technical attack robustness, overlooking crucial real-world factors like deployment environments, system dependencies, and attack feasibility. Attempts at comprehensive AML risk assessment have been limited to domain-specific solutions, preventing application across diverse systems. Addressing these limitations, we present FRAME, the first comprehensive and automated framework for assessing AML risks across diverse ML-based systems. FRAME includes a novel risk assessment method that quantifies AML risks by systematically evaluating three key dimensions: target system's deployment environment, characteristics of diverse AML techniques, and empirical insights from prior research. FRAME incorporates a feasibility scoring mechanism and LLM-based customization for system-specific assessments. Additionally, we developed a comprehensive structured dataset of AML attacks enabling context-aware risk assessment. From an engineering application perspective, FRAME delivers actionable results designed for direct use by system owners with only technical knowledge of their systems, without expertise in AML. We validated it across six diverse real-world applications. Our evaluation demonstrated exceptional accuracy and strong alignment with analysis by AML experts. FRAME enables organizations to prioritize AML risks, supporting secure AI deployment in real-world environments.

对抗攻击风险评估AI安全自动化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。