AIセキュリティポータル K Program
Attacks in Adversarial Machine Learning: A Systematic Survey from the Life-cycle Perspective
Share
Abstract
Adversarial machine learning (AML) studies the adversarial phenomenon of machine learning, which may make inconsistent or unexpected predictions with humans. Some paradigms have been recently developed to explore this adversarial phenomenon occurring at different stages of a machine learning system, such as backdoor attack occurring at the pre-training, in-training and inference stage; weight attack occurring at the post-training, deployment and inference stage; adversarial attack occurring at the inference stage. However, although these adversarial paradigms share a common goal, their developments are almost independent, and there is still no big picture of AML. In this work, we aim to provide a unified perspective to the AML community to systematically review the overall progress of this field. We firstly provide a general definition about AML, and then propose a unified mathematical framework to covering existing attack paradigms. According to the proposed unified framework, we build a full taxonomy to systematically categorize and review existing representative methods for each paradigm. Besides, using this unified framework, it is easy to figure out the connections and differences among different attack paradigms, which may inspire future researchers to develop more advanced attack paradigms. Finally, to facilitate the viewing of the built taxonomy and the related literature in adversarial machine learning, we further provide a website, \ie, \url{http://adversarial-ml.com}, where the taxonomies and literature will be continuously updated.
Turning your weakness into a strength: Watermarking deep neural networks by backdooring
Y. Adi, C. Baum, M. Cisse, B. Pinkas, J. Keshet
Published: 2018
Are image-agnostic universal adversarial perturbations for face recognition difficult to detect?
Akshay Agarwal, Richa Singh, Mayank Vatsa, Nalini Ratha
Published: 2018
How to flip a bit?
Michel Agoyan, Jean-Max Dutertre, Amir-Pasha Mirbaha, David Naccache, Anne-Lise Ribotta, Assia Tria
Published: 2010
Discrete cosine transform
Nasir Ahmed, T. Natarajan, Kamisetty R Rao
Published: 1974
Threat of adversarial attacks on deep learning in computer vision: A survey
N. Akhtar, A. Mian
Published: 2018
Sign bits are all you need for black-box attacks
Abdullah Al-Dujaili, Una-May O’Reilly
Published: 2019
Digital steganography: hiding data within data
Donovan Artz
Published: 2001
Synthesizing robust adversarial examples
Anish Athalye, Logan Engstrom, Andrew Ilyas, Kevin Kwok
Published: 2018
How to backdoor federated learning
Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, Vitaly Shmatikov
Published: 2020
Share