Stateful Defenses for Machine Learning Models Are Not Yet Secure Against Black-box Attacks

被引:3
作者
Feng, Ryan [1 ]
Hooda, Ashish [2 ]
Mangaokar, Neal [1 ]
Fawaz, Kassem [2 ]
Jha, Somesh [2 ]
Prakash, Atul [1 ]
机构
[1] Univ Michigan, Ann Arbor, MI 48109 USA
[2] Univ Wisconsin Madison, Madison, WI USA
来源
PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023 | 2023年
基金
美国国家科学基金会;
关键词
Machine Learning; Adversarial Examples; Security; Black-box Attacks; Stateful Defenses;
D O I
10.1145/3576915.3623116
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Recent work has proposed stateful defense models (SDMs) as a compelling strategy to defend against a black-box attacker who only has query access to the model, as is common for online machine learning platforms. Such stateful defenses aim to defend against black-box attacks by tracking the query history and detecting and rejecting queries that are "similar" and thus preventing black-box attacks from finding useful gradients and making progress towards finding adversarial attacks within a reasonable query budget. Recent SDMs (e.g., Blacklight and PIHA) have shown remarkable success in defending against state-of-the-art black-box attacks. In this paper, we show that SDMs are highly vulnerable to a new class of adaptive black-box attacks. We propose a novel adaptive black-box attack strategy called Oracle-guided Adaptive Rejection Sampling (OARS) that involves two stages: (1) use initial query patterns to infer key properties about an SDM's defense; and, (2) leverage those extracted properties to design subsequent query patterns to evade the SDM's defense while making progress towards finding adversarial inputs. OARS is broadly applicable as an enhancement to existing black-box attacks - we show how to apply the strategy to enhance six common black-box attacks to be more effective against current class of SDMs. For example, OARS-enhanced versions of black-box attacks improved attack success rate against recent stateful defenses from almost 0% to to almost 100% for multiple datasets within reasonable query budgets.
引用
收藏
页码:786 / 800
页数:15
相关论文
共 45 条
[1]  
Amazon, Amazon Rekognition: Automate your image recognition and video analysis with machine learning
[2]  
Andriushchenko M, 2020, Img Proc Comp Vis Re, V12368, P484, DOI 10.1007/978-3-030-58592-1_29
[3]  
Athalye A, 2018, PR MACH LEARN RES, V80
[4]   Robust Malware Detection for Internet of (Battlefield) Things Devices Using Deep Eigenspace Learning [J].
Azmoodeh, Amin ;
Dehghantanha, Ali ;
Choo, Kim-Kwang Raymond .
IEEE TRANSACTIONS ON SUSTAINABLE COMPUTING, 2019, 4 (01) :88-95
[5]   Learning visual similarity for product design with convolutional neural networks [J].
Bell, Sean ;
Bala, Kavita .
ACM TRANSACTIONS ON GRAPHICS, 2015, 34 (04)
[6]  
Brendel W, 2018, Arxiv, DOI arXiv:1712.04248
[7]  
Brown TB, 2018, Arxiv, DOI arXiv:1712.09665
[8]   HopSkipJumpAttack: A Query-Efficient Decision-Based Attack [J].
Chen, Jianbo ;
Jordan, Michael, I ;
Wainwright, Martin J. .
2020 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2020), 2020, :1277-1294
[9]  
Chen Steven, 2020, SPAI '20: Proceedings of the 1st ACM Workshop on Security and Privacy on Artificial Intelligence, P30, DOI 10.1145/3385003.3410925
[10]  
Chen SZ, 2022, Arxiv, DOI arXiv:2205.12134