A Moving Target Defense against Adversarial Machine Learning

被引:9
|
作者
Roy, Abhishek [1 ]
Chhabra, Anshuman [2 ]
Kamhoua, Charles A. [3 ]
Mohapatra, Prasant [2 ]
机构
[1] Univ Calif Davis, Dept Elect & Comp Engn, Davis, CA 95616 USA
[2] Univ Calif Davis, Dept Comp Sci, Davis, CA USA
[3] US Army Res Lab ARL, Network Secur Branch, Adelphi, MD USA
关键词
Adversarial Machine Learning; Moving Target Defense; Bounded Rationality; Cybersecurity;
D O I
10.1145/3318216.3363338
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Adversarial Machine Learning has become the latest threat with the ubiquitous presence of machine learning. In this paper we propose a Moving Target Defense approach to defend against adversarial machine learning, i.e., instead of manipulating the machine learning algorithms, we suggest a switching scheme among machine learning algorithms to defend against adversarial attack. We model the problem as a Stackelberg game between the attacker and the defender. We propose a switching strategy which is the Stackelberg equilibrium of the game. We test our method against rational, and boundedly rational attackers. We show that designing a method against a rational attacker is enough in most scenarios. We show that even under very harsh constraints, e.g., no attack-cost, and availability of attacks which can bring down the accuracy to 0, it is possible to achieve reasonable accuracy in the context of classification. This work shows, that in addition to switching among algorithms, one can think of introducing randomness in tuning parameters, and model choices to achieve better defense against adversarial machine learning.
引用
收藏
页码:383 / 388
页数:6
相关论文
共 50 条
  • [1] Morphence: Moving Target Defense Against Adversarial Examples
    Amich, Abderrahmen
    Eshete, Birhanu
    [J]. 37TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2021, 2021, : 61 - 75
  • [2] Toward Effective Moving Target Defense Against Adversarial AI
    Martin, Peter
    Fan, Jian
    Kim, Taejin
    Vesey, Konrad
    Greenwald, Lloyd
    [J]. 2021 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM 2021), 2021,
  • [3] Segmentation Fault: A Cheap Defense Against Adversarial Machine Learning
    Al Bared, Doha
    Nassar, Mohamed
    [J]. 2021 3RD IEEE MIDDLE EAST AND NORTH AFRICA COMMUNICATIONS CONFERENCE (MENACOMM), 2021, : 37 - 42
  • [4] DeepMTD: Moving Target Defense for Deep Visual Sensing against Adversarial Examples
    Song, Qun
    Yan, Zhenyu
    Tan, Rui
    [J]. ACM TRANSACTIONS ON SENSOR NETWORKS, 2022, 18 (01)
  • [5] Moving Target Defense for Embedded Deep Visual Sensing against Adversarial Examples
    Song, Qun
    Yan, Zhenyu
    Tan, Rui
    [J]. PROCEEDINGS OF THE 17TH CONFERENCE ON EMBEDDED NETWORKED SENSOR SYSTEMS (SENSYS '19), 2019, : 124 - 137
  • [6] DeepMTD: Moving Target Defense for Deep Visual Sensing against Adversarial Examples
    Song, Qun
    Yan, Zhenyu
    Tan, Rui
    [J]. ACM Transactions on Sensor Networks, 2021, 18 (01)
  • [7] A Network Security Classifier Defense: Against Adversarial Machine Learning Attacks
    De Lucia, Michael J.
    Cotton, Chase
    [J]. PROCEEDINGS OF THE 2ND ACM WORKSHOP ON WIRELESS SECURITY AND MACHINE LEARNING, WISEML 2020, 2020, : 67 - 73
  • [8] EI-MTD: Moving Target Defense for Edge Intelligence against Adversarial Attacks
    Qian, Yaguan
    Guo, Yankai
    Shao, Qiqi
    Wang, Jiamin
    Wang, Bin
    Gu, Zhaoquan
    Ling, Xiang
    Wu, Chunming
    [J]. ACM TRANSACTIONS ON PRIVACY AND SECURITY, 2022, 25 (03)
  • [9] Using Undervolting as an on-Device Defense Against Adversarial Machine Learning Attacks
    Majumdar, Saikat
    Samavatian, Mohammad Hossein
    Barber, Kristin
    Teodorescu, Radu
    [J]. 2021 IEEE INTERNATIONAL SYMPOSIUM ON HARDWARE ORIENTED SECURITY AND TRUST (HOST), 2021, : 158 - 169
  • [10] MTDeep: Boosting the Security of Deep Neural Nets Against Adversarial Attacks with Moving Target Defense
    Sengupta, Sailik
    Chakraborti, Tathagata
    Kambhampati, Subbarao
    [J]. DECISION AND GAME THEORY FOR SECURITY, 2019, 11836 : 479 - 491