Adversarial Robustness of Machine Learning-Based Access Control
摘要
As technological systems grow in complexity, the task of managing authorisation and access control becomes increasingly challenging. Machine learning (ML) has emerged as a solution capable of adapting to this landscape by leveraging insights from historical data and promptly determining who should be granted access to specific resources. The integration of machine learning into authorisation and access control systems yields numerous benefits. However, it also introduces new vulnerabilities, notably adversarial attacks. A malicious actor could potentially gain unauthorised access to a resource by manipulating an access request. This paper examines the robustness of Machine Learning-based Access Control (MLBAC) systems against evasion attacks. More specifically, it investigates the feasibility of adversarial attacks in the context of access control and examines the importance of attributes in crafting such requests. Our findings indicate that the access control models we examined exhibit a high susceptibility to adversarial examples. This will serve as a foundation for enhancing the robustness of MLBAC systems through adversarial training. This technique results in a significant improvement in robustness, as evidenced by a reduction in evasion rates of circa 40%. The promising results contribute towards addressing one of the primary challenges associated with MLBAC systems, improving their safety, security and robustness, and contribute to a wider acceptance.