Measuring the False Sense of Security

04/10/2022
by   Carlos Gomes, et al.
0

Recently, several papers have demonstrated how widespread gradient masking is amongst proposed adversarial defenses. Defenses that rely on this phenomenon are considered failed, and can easily be broken. Despite this, there has been little investigation into ways of measuring the phenomenon of gradient masking and enabling comparisons of its extent amongst different networks. In this work, we investigate gradient masking under the lens of its mensurability, departing from the idea that it is a binary phenomenon. We propose and motivate several metrics for it, performing extensive empirical tests on defenses suspected of exhibiting different degrees of gradient masking. These are computationally cheaper than strong attacks, enable comparisons between models, and do not require the large time investment of tailor-made attacks for specific models. Our results reveal metrics that are successful in measuring the extent of gradient masking across different networks

READ FULL TEXT

page 1

page 9

page 16

page 17

page 19

research
02/01/2018

Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples

We identify obfuscated gradients as a phenomenon that leads to a false s...
research
03/15/2022

SoK: Why Have Defenses against Social Engineering Attacks Achieved Limited Success?

Social engineering attacks are a major cyber threat because they often s...
research
02/17/2023

Measuring Equality in Machine Learning Security Defenses

The machine learning security community has developed myriad defenses fo...
research
02/18/2019

On Evaluating Adversarial Robustness

Correctly evaluating defenses against adversarial examples has proven to...
research
01/10/2022

Evaluation of Neural Networks Defenses and Attacks using NDCG and Reciprocal Rank Metrics

The problem of attacks on neural networks through input modification (i....
research
06/03/2022

Gradient Obfuscation Checklist Test Gives a False Sense of Security

One popular group of defense techniques against adversarial attacks is b...
research
02/25/2021

Characterizing the Landscape of COVID-19 Themed Cyberattacks and Defenses

COVID-19 (Coronavirus) hit the global society and economy with a big sur...

Please sign up or login with your details

Forgot password? Click here to reset