Evasion attacks are among the most widely studied attacks within the general domain of Adversarial Machine Learning (AML). While there is a very active line of research on generating new more efficient attacks on unconstrained domains, where attributes of a record can be modified arbitrarily, work on tabular constrained domains is significantly more limited. Specifically, to date, there is no general technique for adapting a given attack generation method to any new tabular constrained domain, while ensuring the validity and evasiveness of the generated adversarial examples. Addressing this issue, this paper introduces the Tabular Constraint Guaranteed Evasion (TCGE) algorithm. Our algorithm harnesses the full evasive power of unconstrained attacks by ensuring that the maximum possible perturbation is applied without violating domain constraints, leading to attacks that are both evasive and valid. TCGE accommodates linear, nonlinear, correlated dependencies, and relational constraints. We incorporate TCGE into white-box and black-box threat models in four constrained domains. TCGE shows its plug-and-play compatibility within various existing unconstrained attacks and guarantees the generation of valid evasive adversarial examples without introducing significant time overheads, making TCGE adaptable also for real-time attack generation methods. Despite its generality, TCGE is demonstrated to be more effective and efficient over a specialized attack method for constrained tabular domains.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Augmented Tabular Adversarial Evasion Attacks with Constraint Satisfaction Guarantees

  • Nour Alhussien,
  • Gagan Agrawal,
  • Ahmed Aleroud

摘要

Evasion attacks are among the most widely studied attacks within the general domain of Adversarial Machine Learning (AML). While there is a very active line of research on generating new more efficient attacks on unconstrained domains, where attributes of a record can be modified arbitrarily, work on tabular constrained domains is significantly more limited. Specifically, to date, there is no general technique for adapting a given attack generation method to any new tabular constrained domain, while ensuring the validity and evasiveness of the generated adversarial examples. Addressing this issue, this paper introduces the Tabular Constraint Guaranteed Evasion (TCGE) algorithm. Our algorithm harnesses the full evasive power of unconstrained attacks by ensuring that the maximum possible perturbation is applied without violating domain constraints, leading to attacks that are both evasive and valid. TCGE accommodates linear, nonlinear, correlated dependencies, and relational constraints. We incorporate TCGE into white-box and black-box threat models in four constrained domains. TCGE shows its plug-and-play compatibility within various existing unconstrained attacks and guarantees the generation of valid evasive adversarial examples without introducing significant time overheads, making TCGE adaptable also for real-time attack generation methods. Despite its generality, TCGE is demonstrated to be more effective and efficient over a specialized attack method for constrained tabular domains.