2022

"Real Attackers Don't Compute Gradients": Bridging the Gap Between Adversarial ML Research and Practice

Apruzzese, Giovanni, Anderson, Hyrum S., Dambra, Savino et al.

Understand

Recent years have seen a proliferation of research on adversarial machine learning.

  • Numerous papers demonstrate powerful algorithmic attacks against a wide variety of machine learning (ML) models, and numerous other papers propose defenses that can withstand most attacks.
  • However, abundant real-world evidence suggests that actual attackers use simple tactics to subvert ML-driven systems, and as a result security practitioners have not prioritized adversarial ML defenses.
  • Motivated by the apparent gap between researchers and practitioners, this position paper aims to bridge the two domains.

Reading the bibliography…