Skip to main content
QUICK REVIEW

[論文レビュー] Ad-versarial: Defeating Perceptual Ad-Blocking

Florian Tramèr, Pascal Dupré|arXiv (Cornell University)|Nov 8, 2018
Internet Traffic Analysis and Secure E-voting被引用数 13
ひとこと要約

本論文は、視覚的コンテンツを用いて広告を検出することを目的とした知覚的広告ブロッカーが、100%の成功率で検出を回避できる敵対的攻撃に対して脆弱であることを示している。著者らは、ウェブおよび音声の文脈において敵対的例を生成することで、ウェブのセキュリティ境界の回避やDDoS攻撃の実行を可能にする深刻なセキュリティ上の欠陥を暴露した。

ABSTRACT

Perceptual ad-blocking is a novel approach that detects online advertisements based on their visual content. Compared to traditional filter lists, the use of perceptual signals is believed to be less prone to an arms race with web publishers and ad networks. We demonstrate that this may not be the case. We describe attacks on multiple perceptual ad-blocking techniques, and unveil a new arms race that likely disfavors ad-blockers. Unexpectedly, perceptual ad-blocking can also introduce new vulnerabilities that let an attacker bypass web security boundaries and mount DDoS attacks. We first analyze the design space of perceptual ad-blockers and present a unified architecture that incorporates prior academic and commercial work. We then explore a variety of attacks on the ad-blocker's detection pipeline, that enable publishers or ad networks to evade or detect ad-blocking, and at times even abuse its high privilege level to bypass web security boundaries. On one hand, we show that perceptual ad-blocking must visually classify rendered web content to escape an arms race centered on obfuscation of page markup. On the other, we present a concrete set of attacks on visual ad-blockers by constructing adversarial examples in a real web page context. For seven ad-detectors, we create perturbed ads, ad-disclosure logos, and native web content that misleads perceptual ad-blocking with 100% success rates. In one of our attacks, we demonstrate how a malicious user can upload adversarial content, such as a perturbed image in a Facebook post, that fools the ad-blocker into removing another users' non-ad content. Moving beyond the Web and visual domain, we also build adversarial examples for AdblockRadio, an open source radio client that uses machine learning to detects ads in raw audio streams.

研究の動機と目的

  • 視覚的コンテンツに基づいて広告を検出するものであり、マークアップに依存しない知覚的広告ブロッカーのセキュリティおよび耐性を調査すること。
  • 敵対的攻撃によって検出を回避するか、高 privileges アクセスを悪用できる知覚的広告ブロッキングにおける脆弱性を同定すること。
  • 従来の仮定とは対照的に、知覚的広告ブロッカーが本質的に兵器レースに対して耐性を示さないことを示すこと。
  • これらの脆弱性の広範な影響、特にDDoS攻撃やクロスオリジンセキュリティ違反の悪用可能性を検討すること。

提案手法

  • 既存の学術的および商業的システムを分析することで、知覚的広告ブロッカーの統一されたアーキテクチャを提案した。
  • 実際のウェブページ環境において、7種類の異なる視覚的広告検出モデルを標的にした敵対的例を設計および実装した。
  • 広告、広告明示ロゴ、およびネイティブウェブコンテンツのための摂動を生成し、知覚的分類器をだますようにした。
  • AdblockRadioという機械学習ベースの音声広告検出器を対象とした敵対的音声例を生成することで、非視覚的ドメインへの攻撃を拡張した。
  • ユーザーがアップロードしたコンテンツ(例:Facebookなど)を含む実世界の条件で攻撃を評価した。
  • 敵対的例が広告ブロッカーに正当な非広告コンテンツを削除させることで、高 privileges 実行環境を悪用できることを示した。

実験結果

リサーチクエスチョン

  • RQ1実際のウェブ環境において、敵対的例を用いて知覚的広告ブロッカーを信頼性高く回避できるか?
  • RQ2知覚的広告ブロッカーは、ウェブのセキュリティ境界を回避できる新たなセキュリティ脆弱性を引き起こすか?
  • RQ3視覚的および音声ドメインにおける敵対的例は、知覚的広告ブロッキングシステムのセキュリティと信頼性をどの程度損なうか?
  • RQ4敵対的コンテンツを用いて、広告ブロッカーが正当な非広告コンテンツを削除させることで操作できるか?
  • RQ5知覚的広告ブロッカーが視覚的分類に依存していることにより、出版者および広告ネットワークとの間で兵器レースに巻き込まれやすくなるのか?

主な発見

  • 著者らは、実際のウェブページ環境において、7種類の異なる知覚的広告検出システムを100%の成功率で回避できる敵対的例を成功裏に生成した。
  • 悪意あるユーザーが摂動を加えた画像(例:Facebook上)をアップロードすることで、他のユーザーの非広告コンテンツが広告ブロッカーによって削除される可能性があり、実世界での悪用可能性を示した。
  • 知覚的広告ブロッカーは、特権昇格攻撃に対して脆弱であり、敵対者がウェブのセキュリティ境界を回避できる。
  • 本研究は、知覚的広告ブロッキングが出版者および広告ネットワークとの間で兵器レースを排除しないことを明らかにした。敵対的攻撃者は視覚的摂動を悪用できるからである。
  • 敵対的攻撃は視覚的コンテンツにとどまらず、AdblockRadioを用いた実証により、音声ストリームに対しても拡張可能であることが示され、音声分類の知覚的検出も同様に不安全であることがわかった。
  • 本研究は、深刻な欠陥を暴露した:知覚的広告ブロッカーの高 privileges レベルは、コンテンツ削除を操作することでDDoSに類似した影響を引き起こす悪用が可能である。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。