Evasion attacks on ML in domains with nonlinear constraints

Mateusz Krzysztoń, Bartosz Bok, Paweł Żakieta, Joanna Kołodziej · 2024

Cybersecurity efforts aim to protect computer systems, especially complex systems with dynamically changing architectures like mobile computational clouds, from digital attacks. The use of machine learning (ML) models in these systems to analyze and process data, allocate resources or monitor and manage infrastructure is increasingly the field of hackers and the target of sophisticated and increasingly difficult-todetect attacks. Adversarial machine learning (AML) is a class of techniques and methods that attempt to "fool" classical ML algorithms by using, among others, deceptive data or modifying the parameters of cyber-physical systems (CPS).This paper presents a new generic evasion attack model for generating targeted attacks on the ML binary classifiers in domains with nonlinear constraints. We used GD (Gradient Descent) and Adam (Adaptive Moment Estimation) optimization algorithms as the most important internal components of two variants of our attack model. Such a model was then evaluated in an experimental analysis. The achieved results show that the new generic evasion attack model effectively generates targeted attacks on ML binary classifiers, utilizing GD and Adam optimization algorithms. This model was evaluated through experimental analysis, demonstrating its potential in cybersecurity contexts. Through this approach, the research contributes significantly to the field of adversarial machine learning by presenting a novel method that challenges the robustness of ML models under specific nonlinear constraints.

Read the paper · More papers on PaperTik