Who is Responsible for Adversarial Defense?
Kishor Datta Gupta Dipankar Dasgupta
Abstract
We have seen a surge in research aims toward adversarial attacks and defenses in AI/ML systems. While it is crucial to formulate new attack methods and devise novel defense strategies for robustness, it is also imperative to recognize who is responsible for implementing, validating and justifying the necessity of these defenses. In particular, which components of the system are vulnerable to what type of adversarial attacks, and the expertise needed to realize the severity of adversarial attacks. Also how to evaluate and address the adversarial challenges in order to recommend defense strategies for different applications. This paper opened a discussion on who should examine and implement the adversarial defenses and the reason behind such efforts.
中文速览
对抗攻击(adversarial attack)威胁着现实中部署的AI/ML系统,但学界在"谁该负责防御"这一问题上一直缺乏清晰讨论。作者系统梳理了对抗攻击的类型与现有防御手段的局限性,并结合实际系统架构,将攻击可能发生的位置划分为五个节点——从物理世界的输入篡改、传感器/I/O层、通信信道、服务器操作系统,到模型部署前植入的后门。研究发现,不同节点的威胁性质迥异,所需的应对专业知识也各不相同:数据科学家负责对抗训练与模型级防御,系统/固件工程师应对传感器层攻击,网络安全专家处理信道层威胁,而后门检测则需要专项测试机制。论文因此呼吁AI工程师、系统工程师与网络安全专家打破壁垒、协同分担防御责任,并指出当前各方在对抗安全领域的职责边界尚未厘清,亟需行业标准与跨领域协作机制加以规范。
原文 arXiv:2106.14152;中英对照 + 大白话阅读 https://aha.fim.ai/paper/2106.14152v1