Skip to main content
QUICK REVIEW

[论文解读] Machine Learning Based Cyber Attacks Targeting on Controlled Information: A Survey

Yuantian Miao, Chao Chen|arXiv (Cornell University)|Feb 16, 2021
Network Security and Intrusion Detection参考文献 133被引用 14
一句话总结

本综述调查了基于机器学习的窃取攻击对受控信息(如用户活动、机器学习模型及认证数据)的影响,通过分析五阶段攻击方法论展开。研究提出了检测、干扰和隔离三类防御策略,强调了隐蔽性与检测难度的挑战,并指出了未来在机器学习驱动系统中保护敏感信息的研究方向。

ABSTRACT

Stealing attack against controlled information, along with the increasing number of information leakage incidents, has become an emerging cyber security threat in recent years. Due to the booming development and deployment of advanced analytics solutions, novel stealing attacks utilize machine learning (ML) algorithms to achieve high success rate and cause a lot of damage. Detecting and defending against such attacks is challenging and urgent so that governments, organizations, and individuals should attach great importance to the ML-based stealing attacks. This survey presents the recent advances in this new type of attack and corresponding countermeasures. The ML-based stealing attack is reviewed in perspectives of three categories of targeted controlled information, including controlled user activities, controlled ML model-related information, and controlled authentication information. Recent publications are summarized to generalize an overarching attack methodology and to derive the limitations and future directions of ML-based stealing attacks. Furthermore, countermeasures are proposed towards developing effective protections from three aspects -- detection, disruption, and isolation.

研究动机与目标

  • 分析机器学习驱动的窃取攻击对受控信息在网络安全领域日益增长的威胁。
  • 对三类受控信息进行分类与分析:用户活动、与机器学习模型相关的数据以及认证信息。
  • 基于通用攻击方法论,识别机器学习窃取攻击的局限性及未来研究方向。
  • 提出并评估检测、干扰和隔离三类防御机制,以减轻此类攻击的影响。
  • 强调由于攻击隐蔽性强且成功率高,亟需提升检测与防护能力。

提出的方法

  • 提出五阶段攻击方法论:侦察、数据收集、特征工程、攻击目标、评估。
  • 将基于机器学习的窃取攻击分为两种模式:通过机器学习模型窃取信息,以及窃取机器学习模型本身(模型重建)。
  • 综述防御技术,包括差分隐私(全局、本地、分布式)以保护训练数据与模型参数。
  • 引入通过粗粒度预测和置信度掩码实现的输出扰动,以干扰模型反演攻击。
  • 应用正则化与混淆技术,隐藏可访问数据源中的敏感信息。
  • 利用对抗训练作为强正则化手段,防御攻击者进行的高级特征工程与基于机器学习的分析。

实验结果

研究问题

  • RQ1基于机器学习的窃取攻击如何系统性地针对受控的用户活动、机器学习模型及认证信息?
  • RQ2在不同类型的受控信息中,机器学习窃取攻击普遍利用的漏洞有哪些?
  • RQ3差分隐私与输出扰动技术如何有效干扰模型反演与成员推断攻击?
  • RQ4当前防御机制在保障服务可用性的同时,确保数据机密性的局限性是什么?
  • RQ5为应对基于机器学习的信息窃取攻击的隐蔽性与演变性,未来需要哪些研究方向?

主要发现

  • 由于攻击具有高度隐蔽性,基于机器学习的窃取攻击日益高效且难以检测,常可绕过传统安全机制。
  • 当存在查询访问时,模型重建攻击可成功从机器学习即服务(MLaaS)平台提取模型参数与训练数据。
  • 记录级别的差分隐私相较于参数级别的差分隐私,能更有效地抵御基于生成对抗网络(GAN)的攻击,尽管两者均能降低信息泄露。
  • 通过粗粒度预测与置信度掩码实现的输出扰动,显著降低了模型反演攻击的成功率。
  • 对抗训练与混淆技术作为有效的正则化手段,可破坏攻击者执行高级特征工程的能力。
  • 通过动态权限控制与访问限制实现的隔离,在阻断侦察阶段有效,但若过度使用,可能降低服务可用性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。