首个评估机器学习防御措施间相互影响的Python工具库
Amulet: a Python Library for Assessing Interactions Among ML Defenses and Risks
- 构建模块化库,统一评估防御措施的预期与意外交互
- 涵盖主流攻击、防御与评估指标,支持新模块扩展
- 适合安全、隐私、公平性交叉研究者使用
机器学习模型面临安全、隐私和公平性等多重风险。现有防御措施通常针对单一风险设计(预期交互),但可能无意中影响对其他无关风险的脆弱性(意外交互)。本文提出Amulet,首个用于评估机器学习防御与风险之间预期和意外交互的Python库。Amulet具备全面性(涵盖代表性攻击、防御与度量)、可扩展性(模块化设计支持新增组件)、一致性(用户友好的输入输出接口)和适用性(可评估新型交互)。满足四项特性后,Amulet为研究防御措施间的交互提供了统一基础,首次实现跨多种风险的意外交互系统性评估。
原文摘要 · Abstract (English)
Machine learning (ML) models are susceptible to various risks to security, privacy, and fairness. Most defenses are designed to protect against each risk individually (intended interactions) but can inadvertently affect susceptibility to other unrelated risks (unintended interactions). We introduce Amulet, the first Python library for evaluating both intended and unintended interactions among ML defenses and risks. Amulet is comprehensive by including representative attacks, defenses, and metrics; extensible to new modules due to its modular design; consistent with a user-friendly API template for inputs and outputs; and applicable for evaluating novel interactions. By satisfying all four properties, Amulet offers a unified foundation for studying how defenses interact, enabling the first systematic evaluation of unintended interactions across multiple risks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。