敌对机器学习中的防御:从生命周期的角度进行系统调查
IEEE transactions on pattern analysis and machine intelligence
|September 17, 2025
概括
机器学习 (ML) 系统面临来自对抗性攻击的安全威胁. 这项调查统一了整个ML生命周期的防御策略,为强大的模型开发提供了新的视角.
科学领域:
- 计算机科学 计算机科学
- 人工智能的人工智能
- 机器学习安全 机器学习安全
背景情况:
- 机器学习 (ML) 系统,特别是深度神经网络,表现出对抗现象,产生不一致和不可理解的预测.
- 这些漏洞带来了重大的安全风险,导致了后门攻击,权重攻击和对抗性例子等攻击范式的发展.
- 现有的防御机制往往是针对单个攻击类型的,这使得整体系统的稳定性评估具有挑战性.
研究的目的:
- 系统地审查ML系统中对抗对手攻击的现有防御范式.
- 为分析和分类防御方法提供统一的生命周期视角.
- 促进开发更全面,更先进的国防战略.
主要方法:
- 将ML系统分解为五个生命周期阶段:预培训,培训,后培训,部署和推断.
- 开发一个清晰的分类法,以分类每个阶段的代表性防御方法.
- 从统一生命周期的角度分析防御机制.
主要成果:
- 一个系统的审查和对抗ML对抗攻击的防御方法的分类.
- 一个统一的生命周期视角,阐明各种防御范式之间的联系和差异.
- 确定研究缺口,并为未来的全面国防战略提供灵感.
结论:
- 统一的生命周期方法对于理解和开发针对ML中各种对抗性攻击的强有力的防御至关重要.
- 拟议的分类学有助于分析现有防御,并指导未来的研究向更综合的解决方案.
- 这项工作为提高机器学习系统的安全性和可靠性提供了基础框架.
相关概念视频
Stereotype Content Model
15.3K
The Stereotype Content Model (SCM) was first proposed by Susan Fiske and her colleagues (Fiske, Cuddy, Glick & Xu, 2002; see also Fiske, 2012 and Fiske, 2017). The SCM specifies that when someone encounters a new group, they will stereotype them based on two metrics: warmth—or that group’s perceived intent, and how likely they are to provide help or inflict harm—and competence—or their ability to carry out that objective. Depending on the warmth-competence...
15.3K
Feedback control systems
687
Feedback control systems are categorized in various ways based on their design, analysis, and signal types.
Linear feedback systems are theoretical models that simplify analysis and design. These systems operate under the principle that their output is directly proportional to their input within certain ranges. For instance, an amplifier in a control system behaves linearly as long as the input signal remains within a specific range. However, most physical systems exhibit inherent nonlinearity...
Linear feedback systems are theoretical models that simplify analysis and design. These systems operate under the principle that their output is directly proportional to their input within certain ranges. For instance, an amplifier in a control system behaves linearly as long as the input signal remains within a specific range. However, most physical systems exhibit inherent nonlinearity...
687
Mechanistic Models: Compartment Models in Algorithms for Numerical Problem Solving
292
Mechanistic models play a crucial role in algorithms for numerical problem-solving, particularly in nonlinear mixed effects modeling (NMEM). These models aim to minimize specific objective functions by evaluating various parameter estimates, leading to the development of systematic algorithms. In some cases, linearization techniques approximate the model using linear equations.
In individual population analyses, different algorithms are employed, such as Cauchy's method, which uses a...
In individual population analyses, different algorithms are employed, such as Cauchy's method, which uses a...
292
Avoidance Learning and Learned Helplessness
2.5K
Avoidance learning and learned helplessness are critical concepts in understanding behavioral responses to negative stimuli.
Avoidance learning occurs when an organism learns that a specific behavior can prevent an unpleasant outcome. For example, a student who receives a bad grade may start studying harder to avoid future poor grades. This behavior persists even when the negative outcome is no longer present. Avoidance learning is powerful because it maintains behavior in the absence of the...
Avoidance learning occurs when an organism learns that a specific behavior can prevent an unpleasant outcome. For example, a student who receives a bad grade may start studying harder to avoid future poor grades. This behavior persists even when the negative outcome is no longer present. Avoidance learning is powerful because it maintains behavior in the absence of the...
2.5K


