{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/evasion-attacks-against-machine-learning-at","title":"Evasion Attacks against Machine Learning at Test Time","arxiv_id":"1708.06131","date":"2017-08-21","proceeding":null,"authors":["Battista Biggio","Igino Corona","Davide Maiorca","Blaine Nelson","Nedim Srndic","Pavel Laskov","Giorgio Giacinto","Fabio Roli"],"abstract":"In security-sensitive applications, the success of machine learning depends\non a thorough vetting of their resistance to adversarial data. In one\npertinent, well-motivated attack scenario, an adversary may attempt to evade a\ndeployed system at test time by carefully manipulating attack samples. In this\nwork, we present a simple but effective gradient-based approach that can be\nexploited to systematically assess the security of several, widely-used\nclassification algorithms against evasion attacks. Following a recently\nproposed framework for security evaluation, we simulate attack scenarios that\nexhibit different risk levels for the classifier by increasing the attacker's\nknowledge of the system and her ability to manipulate attack samples. This\ngives the classifier designer a better picture of the classifier performance\nunder evasion attacks, and allows him to perform a more informed model\nselection (or parameter setting). We evaluate our approach on the relevant\nsecurity task of malware detection in PDF files, and show that such systems can\nbe easily evaded. We also sketch some countermeasures suggested by our\nanalysis.","url_abs":"http://arxiv.org/abs/1708.06131v1","url_pdf":"http://arxiv.org/pdf/1708.06131v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"evasion-attacks-against-machine-learning-at","repo_url":"https://github.com/Koukyosyumei/AIJack","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"machine-learning","task_name":"BIG-bench Machine Learning"},{"task_slug":"malware-detection","task_name":"Malware Detection"},{"task_slug":"model-selection","task_name":"Model Selection"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1708.06131","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}