DEFENSES FOR MACHINE LEARNING MODELS FROM ADVERSARIAL ATTACKS
Svetlana G. Fomicheva, Sergey Valentinovich Bezzateev · T-Comm - Телекоммуникации и Транспорт · 2023
The problems of protection for intelligent information systems are acutely relevant due to their application in the subjects of critical information infrastructure. The most difficult to identify are adversarial attacks on machine learning models, which are carried out during transfer and federative training of already pre-trained models. At the same time, the anatomy of adversarial attacks is rarely covered in the Russian-language segment of publications, and the defenses against them and mechanisms for evaluating protection against attacks on machine learning models are practically absent, which actualizes the need for the analytical review presented in the article. Purpose: the purpose of the study is to conduct an analytical review and a formalized description of the defenses for machine learning models that are the target of adversarial attacks. Results: based on the classification of attacks aimed at machine learning models, the modern principles of their defenses are formalized. Unlike existing publications, our review highlights and summarizes not only the types of attacks on machine learning models, but also the mechanisms of their implementation. The classification of existing methods of protection against adversarial attacks is carried out. Practical relevance: as a result of generalization, the necessary requirements for the construction of models protected from adversarial attacks are formulated. Discussion: The main attention when building protection mechanisms for machine learning models and evaluating their reliability should be focused on countering complex adaptive attacks that clearly identify and target the weakest links of protection.