Securing Machine Learning Models: Notions and Open Issues
Lara Mauri, Ernesto Damiani · 2023
Machine Learning (ML) models are taking the place of conventional algorithms in a wide range of application domains. However, once ML models have been deployed in the field, they can be attacked in ways that are very different from the ones of conventional systems. This chapter reviews some of the techniques that attackers use to compromise ML-based systems at two core phases of the learning process: the training and the inference stages. It provides an overview that, taking into account the current variety and scope of threats and attacks to ML models, will help the security analyst in charge of alleviating them. The chapter introduces some preliminary concepts, including the one of ML lifecycle . It then presents the setting of Adversarial Machine Learning from the point of view context of computer security, and discusses the notions of threats, vulnerabilities, and attacks. The chapter also details common alleviation measures against training-time attacks.