AIセキュリティポータル K Program
Adversarial Attacks on Machine Learning-Aided Visualizations
Share
Abstract
Research in ML4VIS investigates how to use machine learning (ML) techniques to generate visualizations, and the field is rapidly growing with high societal impact. However, as with any computational pipeline that employs ML processes, ML4VIS approaches are susceptible to a range of ML-specific adversarial attacks. These attacks can manipulate visualization generations, causing analysts to be tricked and their judgments to be impaired. Due to a lack of synthesis from both visualization and ML perspectives, this security aspect is largely overlooked by the current ML4VIS literature. To bridge this gap, we investigate the potential vulnerabilities of ML-aided visualizations from adversarial attacks using a holistic lens of both visualization and ML perspectives. We first identify the attack surface (i.e., attack entry points) that is unique in ML-aided visualizations. We then exemplify five different adversarial attacks. These examples highlight the range of possible attacks when considering the attack surface and multiple different adversary capabilities. Our results show that adversaries can induce various attacks, such as creating arbitrary and deceptive visualizations, by systematically identifying input attributes that are influential in ML inferences. Based on our observations of the attack surface characteristics and the attack examples, we underline the importance of comprehensive studies of security issues and defense mechanisms as a call of urgency for the ML4VIS community.
Table2Charts: Recommending charts by learning shared table representations
Zhou, M., Li, Q., He, X., Li, Y., et al.
Published: 2021
Text-to-Viz: Automatic generation of infographics from proportion-related natural language statements
Cui, W., Zhang, X., Wang, Y., Huang, H., Chen, B., et al.
Published: 2020
Follow the clicks: Learning and anticipating mouse interactions during exploratory data analysis
Ottley, A., Garnett, R., Wan, R.
Published: 2019
A survey on ML4VIS: Applying machine learning advances to data visualization
Wang, Q., Chen, Z., Wang, Y., Qu, H.
Published: 2022
DL4SciVis: A state-of-the-art survey on deep learning for scientific visualization
Wang, C., Han, J.
Published: 2023
AI4VIS: Survey on artificial intelligence approaches for data visualization
Wu, A., Wang, Y., Shu, X., Moritz, D., et al.
Published: 2022
Black hat visualization
Correll, M., Heer, J.
Published: 2017
Surfacing visualization mirages
McNutt, A., Kindlmann, G., Correll, M.
Published: 2020
Making machine learning robust against adversarial inputs
Goodfellow, I., McDaniel, P., Papernot, N.
Published: 2018
SoK: Security and privacy in machine learning
Papernot, N., McDaniel, P., Sinha, A., Wellman, M.P.
Published: 2018
Agency plus automation: Designing artificial intelligence into interactive systems
Heer, J.
Published: 2019
Robustness and explainability of artificial intelligence
Hamon, R., Junklewitz, H., Sanchez, I.
Published: 2020
Human-centered artificial intelligence: Reliable, safe & trustworthy
Shneiderman, B.
Published: 2020
Adversarial classification
Dalvi, N., Domingos, P., Sanghai, S., Verma, D.
Published: 2004
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, R. Fergus
Published: 2014
Practical black-box attacks against machine learning
Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., et al.
Published: 2017
Explaining and harnessing adversarial examples
Goodfellow, I.J., Shlens, J., Szegedy, C.
Published: 2015
One pixel attack for fooling deep neural networks
Jiawei Su, Danilo Vasconcellos Vargas, Sakurai Kouichi
Published: 2017.10.25
Poisoning attacks against support vector machines
Biggio, B., Nelson, B., Laskov, P.
Published: 2012
Talking to bots: Symbiotic agency and the case of Tay
Neff, G., Nagy, P.
Published: 2016
Backdoor learning: A survey
Li, Y., Jiang, Y., Li, Z., Xia, S.-T.
Published: 2024
Backdoor Attacks and Countermeasures on Deep Learning: A Comprehensive Review
Yansong Gao, Bao Gia Doan, Zhi Zhang, Siqi Ma, Jiliang Zhang, Anmin Fu, Surya Nepal, Hyoungshick Kim
Published: 2020.7.21
Distillation as a Defense to Adversarial Perturbations against Deep Neural Networks
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, Ananthram Swami
Published: 2015.11.14
Threat of adversarial attacks on deep learning in computer vision: A survey
N. Akhtar, A. Mian
Published: 2018
Analyzing the noise robustness of deep neural networks
Cao, K., Liu, M., Su, H., Wu, J., et al.
Published: 2021
Bluff: Interactively deciphering adversarial attacks on deep neural networks
Das, N., Park, H., Wang, Z.J., Hohman, F., et al.
Published: 2020
Visual analytics of neuron vulnerability to adversarial attacks on convolutional neural networks
Li, Y., Wang, J., Fujiwara, T., Ma, K.-L.
Published: 2023
Where’s my data? Evaluating visualizations with missing data
Song, H., Szafir, D.A.
Published: 2019
The deceptive potential of common design tactics used in data visualizations
Lauer, C., O’Brien, S.
Published: 2020
How deceptive are deceptive visualizations? An empirical analysis of common distortion techniques
Pandey, A.V., Rall, K., Satterthwaite, M.L., Nov, O., Bertini, E.
Published: 2015
Cognitive Biases in Visualizations
Ellis, G.
Published: 2018
Seeing what you believe or believing what you see? Belief biases correlation estimation
Xiong, C., Stokes, C., Kim, Y.-S., Franconeri, S.
Published: 2023
Can visualization alleviate dichotomous thinking? Effects of visual representations on the cliff effect
Helske, J., Helske, S., Cooper, M., Ynnerman, A., Besancon, L.
Published: 2021
The work that visualisation conventions do
Kennedy, H., Hill, R.L., Aiello, G., Allen, W.
Published: 2016
VizLinter: A linter and fixer framework for data visualization
Chen, Q., Sun, F., Xu, X., Chen, Z., et al.
Published: 2022
Annotating line charts for addressing deception
Fan, A., Ma, Y., Mancenido, M., Maciejewski, R.
Published: 2022
Warning, bias may occur: A proposed approach to detecting cognitive bias in interactive visual analytics
Wall, E., Blaha, L.M., Franklin, L., Endert, A.
Published: 2017
NeuroConstruct: 3D reconstruction and visualization of neurites in optical microscopy brain images
Ghahremani, P., Boorboor, S., Mirhosseini, P., Gudisagar, C., et al.
Published: 2022
DeepOrganNet: On-the-fly reconstruction and visualization of 3D / 4D lung models from single-view projections by deep deformation network
Wang, Y., Zhong, Z., Hua, J.
Published: 2020
Measuring domain shift for deep learning in histopathology
Stacke, K., Eilertsen, G., Unger, J., Lundström, C.
Published: 2021
An analysis of automated visual analysis classification: Interactive visualization task inference of cancer genomics domain experts
Gramazio, C.C., Huang, J., Laidlaw, D.H.
Published: 2018
An incremental dimensionality reduction method for visualizing streaming multidimensional data
Fujiwara, T., Chou, J.-K., Shilpika, S., Xu, P., et al.
Published: 2020
Visualizing time-dependent data using dynamic t-SNE
Rauber, P.E., Falcão, A.X., Telea, A.C.
Published: 2016
Parametric dimension reduction by preserving local structure
Lai, C.-H., Kuo, M.-F., Lien, Y.-H., Su, K.-A., Wang, Y.-S.
Published: 2022
Parametric UMAP embeddings for representation and semi-supervised learning
Sainburg, T., McInnes, L., Gentner, T.Q.
Published: 2021
Learning a parametric embedding by preserving local structure
Van der Maaten, L.
Published: 2009
ParaDime: A framework for parametric dimensionality reduction
Hinterreiter, A., Humer, C., Kainz, B., Streit, M.
Published: 2023
DMT-EV: An explainable deep network for dimension reduction
Zang, Z., Cheng, S., Xia, H., Li, L., Sun, Y., Xu, Y., Shang, L., Sun, B., Li, S.Z.
Published: 2024
MultiVision: Designing analytical dashboards with deep learning based recommendation
Wu, A., Wang, Y., Zhou, M., He, X., et al.
Published: 2022
ChartSeer: Interactive steering exploratory visual analysis with machine intelligence
Zhao, J., Fan, M., Feng, M.
Published: 2022
PlotThread: Creating expressive storyline visualizations using reinforcement learning
Tang, T., Li, R., Wu, X., Liu, S., et al.
Published: 2021
A deep generative model for graph layout
Kwon, O.-H., Ma, K.-L.
Published: 2020
Fast and accurate CNN-based brushing in scatterplots
Fan, C., Hauser, H.
Published: 2018
Reverse-engineering visualizations: Recovering visual encodings from chart images
Poco, J., Heer, J.
Published: 2017
ScatterNet: A deep subjective similarity model for visual analysis of scatterplots
Ma, Y., Tung, A.K., Wang, W., Gao, X., et al.
Published: 2018
A survey of visual analytic pipelines
Wang, X.-M., Zhang, T.-Y., Ma, Y.-X., Xia, J., Chen, W.
Published: 2016
Context visualization for visual data mining
Huang, M.L., Nguyen, Q.V.
Published: 2008
Cyber-attack modeling analysis techniques: An overview
Al-Mohannadi, H., Mirza, Q., Namanya, A., Awan, I., Cullen, A., Disso, J.
Published: 2016
The role of uncertainty, awareness, and trust in visual analytics
Sacha, D., Senaratne, H., Kwon, B.C., Ellis, G., Keim, D.A.
Published: 2016
User-adaptive information visualization: Using eye gaze data to infer visualization tasks and user cognitive abilities
Steichen, B., Carenini, G., Conati, C.
Published: 2013
Human factors evaluation of level 2 and level 3 automated driving concepts: Past research, state of automation technology, and emerging system concepts
Trimble, T.E., Bishop, R., Morgan, J.F., et al.
Published: 2014
Toward a quantitative survey of dimension reduction techniques
Espadoto, M., Martins, R.M., Kerren, A., Hirata, N.S.T., Telea, A.C.
Published: 2021
Activation functions in deep learning: A comprehensive survey and benchmark
S.R. Dubey, S.K. Singh, B.B. Chaudhuri
Published: 2022
Visual interaction with dimensionality reduction: A structured literature analysis
Sacha, D., Zhang, L., Sedlmair, M., Lee, J.A., et al.
Published: 2017
Supporting analysis of dimensionality reduction results with contrastive learning
Fujiwara, T., Kwon, O.-H., Ma, K.-L.
Published: 2020
Vega-Lite: A grammar of interactive graphics
Satyanarayan, A., Moritz, D., Wongsuphasawat, K., Heer, J.
Published: 2017
Unsupervised user stance detection on Twitter
Darwish, K., Stefanov, P., Aupetit, M., Nakov, P.
Published: 2020
The state of the art in enhancing trust in machine learning models with the use of visualizations
Chatzimparmpas, A., Martins, R.M., Jusufi, I., Kucher, K., et al.
Published: 2020
Views on visualization
Van Wijk, J.J.
Published: 2006
Selection-bias-corrected visualization via dynamic reweighting
Borland, D., Zhang, J., Kaul, S., Gotz, D.
Published: 2021
Share