揭示机器学习中敌手协同攻击的机制与影响
SoK: Colluding Adversaries in Machine Learning Pipelines
- 构建跨训练与推理阶段敌手的协同攻击框架
- 提出可预测协同攻击潜力的判断准则
- 适用于安全、隐私与公平性研究者
机器学习模型面临多种安全、隐私和公平性风险。具有不同特征(目标、知识、能力)的敌手可通过执行单一攻击来放大其他攻击效果。现有研究缺乏系统框架来探索敌手间的协同行为及其特征影响。本文提出一个涵盖(a)训练与推理阶段敌手间协同,以及(b)推理阶段敌手间协同的框架。该框架考虑了促成协同的关键因素,提出一套基于这些因素推测协同潜力的指南。利用该指南,我们解释了已有工作中的协同现象,推测了未被探索的协同场景,并对其中五个案例进行了实证验证。最后,讨论了敌手特征如何影响协同可能性。
原文摘要 · Abstract (English)
Machine learning (ML) models are susceptible to various security, privacy, and fairness risks. Adversaries with different characteristics (i.e., objectives, knowledge, and capabilities) can collude by executing one attack to amplify others. Existing work lacks a systematic framework to explore collusion among adversaries, and to study the implications of the adversaries' characteristics. We present a framework covering collusion (a) between train- and inference-time adversaries, and (b) among inference-time adversaries. Our framework accounts for factors enabling collusion between adversaries. We propose a guideline to conjecture about the potential for collusion using enabling factors. We use it to explain prior work, conjecture about unexplored collusions, and empirically validate five such cases. Finally, we discuss how adversaries' characteristics influence the potential for collusion.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。