Towards more Practical Threat Models in Artificial Intelligence Security

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Grosse, Kathrin, Bieringer, Lukas, Besold, Tarek Richard, Alahi, Alexandre
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916177353113600
author Grosse, Kathrin
Bieringer, Lukas
Besold, Tarek Richard
Alahi, Alexandre
author_facet Grosse, Kathrin
Bieringer, Lukas
Besold, Tarek Richard
Alahi, Alexandre
contents Recent works have identified a gap between research and practice in artificial intelligence security: threats studied in academia do not always reflect the practical use and security risks of AI. For example, while models are often studied in isolation, they form part of larger ML pipelines in practice. Recent works also brought forward that adversarial manipulations introduced by academic attacks are impractical. We take a first step towards describing the full extent of this disparity. To this end, we revisit the threat models of the six most studied attacks in AI security research and match them to AI usage in practice via a survey with 271 industrial practitioners. On the one hand, we find that all existing threat models are indeed applicable. On the other hand, there are significant mismatches: research is often too generous with the attacker, assuming access to information not frequently available in real-world settings. Our paper is thus a call for action to study more practical threat models in artificial intelligence security.
format Preprint
id arxiv_https___arxiv_org_abs_2311_09994
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Towards more Practical Threat Models in Artificial Intelligence Security
Grosse, Kathrin
Bieringer, Lukas
Besold, Tarek Richard
Alahi, Alexandre
Cryptography and Security
Artificial Intelligence
Recent works have identified a gap between research and practice in artificial intelligence security: threats studied in academia do not always reflect the practical use and security risks of AI. For example, while models are often studied in isolation, they form part of larger ML pipelines in practice. Recent works also brought forward that adversarial manipulations introduced by academic attacks are impractical. We take a first step towards describing the full extent of this disparity. To this end, we revisit the threat models of the six most studied attacks in AI security research and match them to AI usage in practice via a survey with 271 industrial practitioners. On the one hand, we find that all existing threat models are indeed applicable. On the other hand, there are significant mismatches: research is often too generous with the attacker, assuming access to information not frequently available in real-world settings. Our paper is thus a call for action to study more practical threat models in artificial intelligence security.
title Towards more Practical Threat Models in Artificial Intelligence Security
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2311.09994