Adversarial machine learning (AML) studies the adversarial phenomenon of machine learning, which may make inconsistent or unexpected predictions with humans. Some paradigms have been recently developed to explore this adversarial phenomenon occurring at different stages of a machine learning system, such as backdoor attack occurring at the pre-training, in-training and inference stage; weight attack occurring at the post-training, deployment and inference stage; adversarial attack occurring at the inference stage. However, although these adversarial paradigms share a common goal, their developments are almost independent, and there is still no big picture of AML. In this work, we aim to provide a unified perspective to the AML community to systematically review the overall progress of this field. We firstly provide a general definition about AML, and then propose a unified mathematical framework to covering existing attack paradigms. According to the proposed unified framework, we build a full taxonomy to systematically categorize and review existing representative methods for each paradigm. Besides, using this unified framework, it is easy to figure out the connections and differences among different attack paradigms, which may inspire future researchers to develop more advanced attack paradigms. Finally, to facilitate the viewing of the built taxonomy and the related literature in adversarial machine learning, we further provide a website, \ie, \url{http://adversarial-ml.com}, where the taxonomies and literature will be continuously updated.
翻译:对抗机器学习(Adversarial Machine Learning, AML)研究机器学习中出现的对抗现象,该现象可能导致模型产生与人类不一致或不可预测的预测结果。近年来,研究者提出了多种范式来探索机器学习系统不同阶段出现的对抗现象,例如发生在预训练、训练中和推理阶段的后门攻击;发生在训练后、部署和推理阶段的权重攻击;以及发生在推理阶段的对抗攻击。然而,尽管这些对抗范式具有共同目标,但它们的发展几乎相互独立,目前仍缺乏AML的宏观图景。本文旨在为AML领域提供统一视角,系统性地回顾该领域的整体进展。我们首先给出AML的通用定义,随后提出一个统一的数学框架以覆盖现有攻击范式。基于该统一框架,我们构建了一套完整的分类体系,系统性地对每个范式的代表性方法进行分类与评述。此外,借助该统一框架,我们能够清晰阐明不同攻击范式间的联系与差异,这可为未来研究者开发更先进的攻击范式提供启发。最后,为便于查阅所构建的分类体系及对抗机器学习领域的相关文献,我们进一步提供了网站(即 http://adversarial-ml.com),该网站将持续更新分类体系与文献。