ICASSP 2023accepted0 citations

Forensics for Adversarial Machine Learning Through Attack Mapping Identification

Allen Yan, Jinsub Kim, Raviv Raich

Abstract

This paper considers the problem of performing post-attack forensic analysis for a test-time attack on a machine learning model. A test-time attack can be represented as a mapping that receives a benign test example as the input and outputs a falsified version of it. Given a set of attacked examples in the post-attack time, our objective is to identify the correct attack mapping among the collection of candidate attack strategies with diverse objectives and constraints. We present an attack mapping identification method that utilizes a pre-attack example recovery mechanism as a feature extraction method. Using numerical experiments, we demonstrate the effectiveness of the proposed approach in detecting the correct attack mapping among a number of different candidate attack strategies.

BibTeX
@inproceedings{icassp2023_forensicsforadve,
  title = {Forensics for Adversarial Machine Learning Through Attack Mapping Identification},
  author = {Allen Yan and Jinsub Kim and Raviv Raich},
  booktitle = {ICASSP 2023},
  year = {2023}
}