Randomness in ML Defenses Helps Persistent Attackers and Hinders Evaluators

02/27/2023
by   Keane Lucas, et al.
0

It is becoming increasingly imperative to design robust ML defenses. However, recent work has found that many defenses that initially resist state-of-the-art attacks can be broken by an adaptive adversary. In this work we take steps to simplify the design of defenses and argue that white-box defenses should eschew randomness when possible. We begin by illustrating a new issue with the deployment of randomized defenses that reduces their security compared to their deterministic counterparts. We then provide evidence that making defenses deterministic simplifies robustness evaluation, without reducing the effectiveness of a truly robust defense. Finally, we introduce a new defense evaluation framework that leverages a defense's deterministic nature to better evaluate its adversarial robustness.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/11/2023

Investigating Stateful Defenses Against Black-Box Adversarial Examples

Defending machine-learning (ML) models against white-box adversarial att...
research
12/11/2018

Mix'n'Squeeze: Thwarting Adaptive Adversarial Samples Using Randomized Squeezing

Deep Learning (DL) has been shown to be particularly vulnerable to adver...
research
09/30/2019

Defense in Depth: The Basics of Blockade and Delay

Given that individual defenses are rarely sufficient, defense-in-depth i...
research
05/02/2019

A Survey of Moving Target Defenses for Network Security

Network defense techniques based on traditional tools, techniques, and p...
research
01/09/2018

A Survey among Network Operators on BGP Prefix Hijacking

BGP prefix hijacking is a threat to Internet operators and users. Severa...
research
06/19/2022

On the Limitations of Stochastic Pre-processing Defenses

Defending against adversarial examples remains an open problem. A common...
research
04/12/2019

Adversarial Learning in Statistical Classification: A Comprehensive Review of Defenses Against Attacks

With the wide deployment of machine learning (ML) based systems for a va...

Please sign up or login with your details

Forgot password? Click here to reset