Machine Learning Security: Threats, Countermeasures, and Evaluations

被引:89
作者
Xue, Mingfu [1 ]
Yuan, Chengxiang [1 ]
Wu, Heyi [2 ]
Zhang, Yushu [1 ]
Liu, Weiqiang [3 ]
机构
[1] Nanjing Univ Aeronaut & Astronaut, Coll Comp Sci & Technol, Nanjing 210016, Peoples R China
[2] Nanjing Upsec Network Secur Technol Res Inst Co L, Nanjing 211100, Peoples R China
[3] Nanjing Univ Aeronaut & Astronaut, Coll Elect & Informat Engn, Nanjing 210016, Peoples R China
来源
IEEE ACCESS | 2020年 / 8卷
基金
中国国家自然科学基金;
关键词
Machine learning; Security; Data models; Machine learning algorithms; Training; Training data; Prediction algorithms; Artificial intelligence security; poisoning attacks; backdoor attacks; adversarial examples; privacy-preserving machine learning; POISONING ATTACKS; DEFENSES;
D O I
10.1109/ACCESS.2020.2987435
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Machine learning has been pervasively used in a wide range of applications due to its technical breakthroughs in recent years. It has demonstrated significant success in dealing with various complex problems, and shows capabilities close to humans or even beyond humans. However, recent studies show that machine learning models are vulnerable to various attacks, which will compromise the security of the models themselves and the application systems. Moreover, such attacks are stealthy due to the unexplained nature of the deep learning models. In this survey, we systematically analyze the security issues of machine learning, focusing on existing attacks on machine learning systems, corresponding defenses or secure learning techniques, and security evaluation methods. Instead of focusing on one stage or one type of attack, this paper covers all the aspects of machine learning security from the training phase to the test phase. First, the machine learning model in the presence of adversaries is presented, and the reasons why machine learning can be attacked are analyzed. Then, the machine learning security-related issues are classified into five categories: training set poisoning; backdoors in the training set; adversarial example attacks; model theft; recovery of sensitive training data. The threat models, attack approaches, and defense techniques are analyzed systematically. To demonstrate that these threats are real concerns in the physical world, we also reviewed the attacks in real-world conditions. Several suggestions on security evaluations of machine learning systems are also provided. Last, future directions for machine learning security are also presented.
引用
收藏
页码:74720 / 74742
页数:23
相关论文
共 50 条
  • [1] Smart Grid Security and Privacy: From Conventional to Machine Learning Issues (Threats and Countermeasures)
    Haji Mirzaee, Parya
    Shojafar, Mohammad
    Cruickshank, Haitham
    Tafazolli, Rahim
    IEEE ACCESS, 2022, 10 : 52922 - 52954
  • [2] Security and Privacy in IoT Using Machine Learning and Blockchain: Threats and Countermeasures
    Waheed, Nazar
    He, Xiangjian
    Ikram, Muhammad
    Usman, Muhammad
    Hashmi, Saad Sajid
    ACM COMPUTING SURVEYS, 2021, 53 (06)
  • [3] Machine Learning Security in Industry: A Quantitative Survey
    Grosse, Kathrin
    Bieringer, Lukas
    Besold, Tarek R.
    Biggio, Battista
    Krombholz, Katharina
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 1749 - 1762
  • [4] Artificial Intelligence Security: Threats and Countermeasures
    Hu, Yupeng
    Kuang, Wenxin
    Qin, Zheng
    Li, Kenli
    Zhang, Jiliang
    Gao, Yansong
    Li, Wenjia
    Li, Keqin
    ACM COMPUTING SURVEYS, 2023, 55 (01)
  • [5] Deep Neural Backdoor in Semi-Supervised Learning: Threats and Countermeasures
    Yan, Zhicong
    Wu, Jun
    Li, Gaolei
    Li, Shenghong
    Guizani, Mohsen
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 : 4827 - 4842
  • [6] Virtual network security: threats, countermeasures, and challenges
    Bays, Leonardo Richter
    Oliveira, Rodrigo Ruas
    Barcellos, Marinho Pilla
    Gaspary, Luciano Paschoal
    Mauro Madeira, Edmundo Roberto
    JOURNAL OF INTERNET SERVICES AND APPLICATIONS, 2015, 6
  • [7] Dataset Security for Machine Learning: Data Poisoning, Backdoor Attacks, and Defenses
    Goldblum, Micah
    Tsipras, Dimitris
    Xie, Chulin
    Chen, Xinyun
    Schwarzschild, Avi
    Song, Dawn
    Madry, Aleksander
    Li, Bo
    Goldstein, Tom
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2023, 45 (02) : 1563 - 1580
  • [8] Security Threats and Countermeasures in Software Defined Networks
    Ahmed, Adnan
    Manzoor, Adnan
    Halepoto, Imtiaz Ali
    Abbas, Fizza
    Rajput, Ubaidullah
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2018, 18 (04): : 69 - 74
  • [9] Web Application Security: Threats, Countermeasures, and Pitfalls
    Huang, Hsiu-Chuan
    Zhang, Zhi-Kai
    Cheng, Hao-Wen
    Shieh, Shiuhpyng Winston
    COMPUTER, 2017, 50 (06) : 81 - 85
  • [10] Recent Advancements in Microarchitectural Security: Review of Machine Learning Countermeasures
    Sayadi, Hossein
    Wang, Han
    Miari, Tahereh
    Makrani, Hosein Mohammadi
    Aliasgari, Mehrdad
    Rafatirad, Setareh
    Homayoun, Houman
    2020 IEEE 63RD INTERNATIONAL MIDWEST SYMPOSIUM ON CIRCUITS AND SYSTEMS (MWSCAS), 2020, : 949 - 952