Survey on adversarial attacks and defenses for images, graphs, and text.
problem Adversarial examples threaten the safety of deep learning applications.
method Review of adversarial attack and defense mechanisms for images, graphs, and text.
result Systematic overview of adversarial attacks and countermeasures.
Study evaluates robot-vision deep learning safety, proposing countermeasures.
problem Vulnerability of robot-vision systems to adversarial examples.
method Empirical analysis and computationally efficient countermeasure.
result Deep networks violate smoothness assumption, making them vulnerable to adversarial examples.
Face recognition systems are vulnerable to composite face reconstruction attacks.
problem Vulnerability of face recognition systems to composite face reconstruction attacks.
method Assumed attacker uses composite face parts to reconstruct faces faster and more efficiently.
result Current face recognition systems are extremely vulnerable to random search attacks.
This paper presents the Speech Technology Center (STC) replay attack detection systems proposed for Automatic Speaker Verification Spoofing and Countermeasures Challenge 2017. In this study we focused on comparison of different spoofing detection approaches. These were GMM based methods, high level features extraction …
Study uses spoofing countermeasures to assess speech processing artifacts in voice conversion.
problem Difficulty in objectively assessing speech processing artifacts in voice conversion.
method Configured a constant-Q cepstral coefficient (CQC) model to measure artifact extent.
result Identified two clusters of VCC'18 entries: low-quality with detectable artifacts and higher quality with less artifacts.
This study combines ASV and CM systems for better performance using reinforcement learning.
problem Improving the combined performance of ASV and CM systems for better t-DCF measure.
method Training ASV and CM components together using reinforcement learning.
result Training ASV and CM components together improves the performance of the combined system.
New metric t-DCF improves ASVspoof challenge results by considering spoofing attack prior.
problem Shortcomings of EER metric in assessing CMs and ASV together.
method Developed t-DCF metric with 6 parameters to assess ASV and CMs together.
result t-DCF shows different rankings for higher spoofing attack priors.
Proposes a method for private aggregation in heterogeneous federated learning.
problem Ensuring resilience to Byzantine clients and maintaining client data privacy in federated learning with heterogeneous data.
method Careful co-design of verifiable secret sharing, secure aggregation, and private information retrieval scheme.
result Achieves information-theoretic privacy guarantees and Byzantine resilience under data heterogeneity.
Survey on adversarial attacks and defenses in deep learning.
problem Vulnerability of deep learning systems to adversarial examples.
method Discussion on different types of adversarial attacks and countermeasures.
result Challenges and inefficiencies in current countermeasures.
TG-PSM morphs encrypted traffic to reduce traffic analysis accuracy.
problem Traffic analysis on encrypted traffic reveals sensitive information.
method Clusters websites, finds target sites, morphs traffic using greedy algorithm.
result TG-PSM reduces attacker's accuracy significantly with low overhead.
This paper presents the Speech Technology Center (STC) systems submitted to Automatic Speaker Verification Spoofing and Countermeasures (ASVspoof) Challenge 2015. In this work we investigate different acoustic feature spaces to determine reliable and robust countermeasures against spoofing attacks. In addition to the c…
Researchers develop attacks to steal machine learning hyperparameters.
problem Stealing confidential hyperparameters in machine learning models.
method Proposed attacks on various machine learning algorithms, evaluated both theoretically and empirically.
result Successfully steal hyperparameters from machine learning models.
Study reveals mutual reinforcement between adversarial inputs and poisoned models.
problem Understanding and mitigating vulnerabilities of deep learning models.
method Developed a new attack model to jointly optimize adversarial inputs and poisoned models.
result Mutual reinforcement effects between adversarial inputs and poisoned models significantly amplify each other's effectiveness.
Deep learning models are vulnerable to adversarial examples that can fool them.
problem Vulnerability of deep learning models to adversarial examples in safety-critical environments.
method Review and taxonomy of methods for generating adversarial examples, countermeasures, and challenges.
result Deep learning models are vulnerable to adversarial examples that can fool them.
Feature selection can be compromised by poisoned training data, requiring new countermeasures.
problem Security of feature selection in adversarial machine learning settings.
method Investigation of popular feature selection methods (LASSO, ridge regression, elastic net) under poisoned training data.
result Popular feature selection methods can be significantly compromised by a small percentage of poisoned training data.
Growing interest in automatic speaker verification (ASV)systems has lead to significant quality improvement of spoofing attackson them. Many research works confirm that despite the low equal er-ror rate (EER) ASV systems are still vulnerable to spoofing attacks. Inthis work we overview different acoustic feature spaces…
This paper models London's real estate market trends and identifies key factors influencing house prices.
problem Complex factors influencing London's real estate prices are not well understood.
method Developed a housing price model using principal components analysis to handle multicollinearity.
result Identified the most important factor affecting house prices per square meter.
Machine learning (ML) models may be deemed confidential due to their sensitive training data, commercial value, or use in security applications. Increasingly often, confidential ML models are being deployed with publicly accessible query interfaces. ML-as-a-service ("predictive analytics") systems are an example: Some …
Fawkes protects images from unauthorized facial recognition models.
problem Unauthorized training of facial recognition models poses privacy risks.
method Fawkes adds imperceptible pixel-level changes (cloaks) to images before release.
result Fawkes can protect images from misidentification by 95% and 80% even when clean images are leaked.
It is well known that speaker verification systems are subject to spoofing attacks. The Automatic Speaker Verification Spoofing and Countermeasures Challenge -- ASVSpoof2015 -- provides a standard spoofing database, containing attacks based on synthetic speech, along with a protocol for experiments. This paper describe…
Adds layers to NNs to protect them from reverse engineering.
problem Extracting the underlying model of a Neural Network.
method Introducing parasitic layers that approximate a noisy identity mapping with a Convolutional NN.
result The protected NN's predictions remain mostly unchanged while making reverse-engineering more complex.
This paper explores how to fool ECG diagnosis systems with adversarial ECGs.
problem Vulnerability of DNN-powered ECG diagnosis systems to adversarial attacks.
method Analyzed ECG properties to design effective adversarial attacks under two models.
result Demonstrates weaknesses in DNN-powered ECG diagnosis systems under adversarial attacks.
This paper explores RL for cyber defense in SDN, resisting poisoning attacks.
problem Adversaries exploit ML adaptability to poison training and evade classification.
method Investigates RL algorithms for autonomous cyber defense in SDN, studying various attack types.
result RL agents can effectively react to poisoning attacks in SDN.
This paper evaluates targeted data poisoning attacks by focusing on the hardest samples, improving evaluation and defense strategies.
problem The effectiveness of targeted data poisoning attacks is often overestimated due to average evaluation methods.
method The paper introduces metrics to identify the hardest and easiest to poison samples based on clean model information.
result The proposed metrics reliably stratify samples by poisoning vulnerability, enabling rigorous worst-case evaluation and proactive defense.
Online surveillance detects systemic risk in financial markets.
problem Detecting and monitoring systemic risk in financial markets.
method Online monitoring procedures for multiple series, controlling for false rejections.
result Procedures allow timely detection of financial distress.
Paper examines Go AI robustness against adversarial attacks.
problem Superhuman Go AIs are vulnerable to simple adversarial strategies.
method Three defenses tested: adversarial training, iterated adversarial training, and changing network architecture.
result No defense is robust against newly trained adversaries, and attacks are similar to cyclic attacks.
Deep learning improves Android malware detection.
problem Detecting and preventing Android malware.
method Review of static, dynamic, and hybrid deep learning approaches.
result Identifies strengths and weaknesses of deep learning methods.
This paper tackles adversarial reinforcement learning in cyber defence with partial observability.
problem Adversarial manipulation of reinforcement learning agents in autonomous cyber defence.
method Proposes an inversion defence method to counteract causative attacks under partial observability.
result The proposed inversion defence method effectively reduces the impact of adversarial attacks without affecting non-attack training scenarios.
A new system detects audio replay attacks with high accuracy.
problem Detecting and preventing audio replay attacks in speaker verification systems.
method Proposes Attentive Filtering Network combining attention-based filtering and ResNet classifier.
result Achieves EER of 8.99% on ASVspoof 2017 Version 2.0 dataset.
Class imbalance is a challenging issue in practical classification problems for deep learning models as well as traditional models. Traditionally successful countermeasures such as synthetic over-sampling have had limited success with complex, structured data handled by deep learning models. In this paper, we propose D…
Paper explores how poisoning data can increase privacy risks in machine learning models.
problem Increasing privacy risks of benign training samples through data poisoning attacks.
method Proposes generic and optimization-based attacks to amplify membership exposure.
result Demonstrates substantial increase in membership inference precision with minimal model performance degradation.
Study finds environmental liability insurance reduces industrial carbon emissions.
problem Reduction of industrial carbon emissions.
method Two-way fixed effect model using provincial (city) level panel data from 2010 to 2020.
result Environmental liability insurance reduces industrial carbon emissions at both direct and indirect levels, with varying effects.
A new method approximates loss functions asymmetrically to prevent catastrophic forgetting.
problem Catastrophic forgetting in deep neural networks.
method Approximating a true loss function using an asymmetric quadratic function with one side overestimated.
result Achieves state-of-the-art accuracy close to upper-bound performance on benchmark datasets.
Behavioral malware clustering can be compromised by poisoning attacks.
problem Security of clustering algorithms for malware analysis.
method Investigated poisoning attacks on behavioral malware clustering.
result Behavioral malware clustering is vulnerable to poisoning attacks.
Graph neural networks are vulnerable to adversarial attacks by manipulating graph structure.
problem Vulnerability of Graph Neural Networks to adversarial attacks.
method Categorization and review of existing attacks and defenses.
result Developed a repository for empirical studies on graph adversarial attacks and defenses.
New method protects neural networks from adversarial attacks without generating adversarial examples.
problem Vulnerability of neural networks to adversarial examples.
method Entropic retraining, inspired by information theory.
result Significant increase in NNs' security and robustness.
Poisoning attacks can undermine fairness in machine learning models.
problem Poisoning attacks can introduce classification disparities among different groups in data.
method Developed a gradient-based poisoning attack framework to target algorithmic fairness.
result Demonstrated the effectiveness of poisoning attacks in both white-box and black-box scenarios.
Paper improves anomaly detection and categorization in multi-cloud environments.
problem Differentiating among different types of attacks for better defense.
method Used supervised machine learning techniques (LR and RF) on a public dataset.
result More than 99% detection accuracy and 93.6% categorization accuracy.
PAC-MCTS addresses biased search in LLM-guided planning by dynamically pruning.
problem Systematic biases in LLMs lead to inefficient and unsafe search in deep planning tasks.
method Formulates node expansion as BAI under bounded bias, derives sample complexity bounds, and proposes PAC-MCTS for dynamic confidence bounds.
result PAC-MCTS improves robustness and efficiency by up to 78% fewer API evaluations and 3x higher sample efficiency.
New method optimizes weights and quantizers in ternary neural networks.
problem Reducing model size and computational cost in deep neural networks.
method Simultaneous optimization of weights and quantizers using truncated Gaussian approximation.
result 3.9-2.16% accuracy loss in ImageNet classification tasks.
Proposes a deep tree-ensemble model for multi-output prediction.
problem Lack of efficient solutions for multi-output prediction.
method Integrates tree-embeddings into deep tree-ensembles for structured output prediction.
result Superior performance in multi-label classification and multi-target regression tasks.
New adversarial training enhances malware detectors against various attacks.
problem Vulnerability of malware detectors to evasion attacks.
method Proposes a mixture of attacks and adversarial training to improve deep neural networks.
result Significantly enhances robustness of deep neural networks against a wide range of attacks.
Poisoning attack is identified as a severe security threat to machine learning algorithms. In many applications, for example, deep neural network (DNN) models collect public data as the inputs to perform re-training, where the input data can be poisoned. Although poisoning attack against support vector machines (SVM) h…
Paper detects adversarial speech inputs with high accuracy.
problem Adversarial attacks on ASR systems.
method Uncertainty quantification using neural networks.
result Detection accuracy of adversarial inputs over 0.99.
New study tackles free-rider attacks in federated learning models.
problem Free-rider attacks compromise federated learning models by non-contributing to data updates.
method Theoretical and experimental analysis of iterative federated learning schemes, including FedAvg and FedProx.
result Formal guarantees for free-rider attacks to converge to aggregated models of fair participants.
ReRe detects anomalies in real-time for time series data.
problem Real-time anomaly detection for time series data requires human intervention or domain knowledge and high computation complexity.
method ReRe uses two lightweight LSTM models to predict and determine anomalies based on historical data and adaptive thresholds.
result ReRe detects anomalies in real-time without requiring human intervention or domain knowledge.
This paper characterizes adversarial examples in deep learning.
problem Security threats posed by adversarial attacks in deep learning systems.
method Statistical characterization of adversarial examples, easy and hard categorization of attacks, extensive experimental study.
result Adversarial attacks behave differently under different hyperparameters and frameworks.
Trapdoors in neural networks attract adversarial attacks, making them easier to detect.
problem Adversarial attacks on neural networks are difficult to detect and defend against.
method Intentionally inject trapdoors to attract adversarial attacks, then detect them based on feature similarity.
result Trapdoor-protected models can accurately detect adversarial examples with minimal impact on normal classification.