{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/failure-modes-in-machine-learning-systems","title":"Failure Modes in Machine Learning Systems","arxiv_id":"1911.11034","date":"2019-11-25","proceeding":null,"authors":["Ram Shankar Siva Kumar","David O Brien","Kendra Albert","Salomé Viljöen","Jeffrey Snover"],"abstract":"In the last two years, more than 200 papers have been written on how machine learning (ML) systems can fail because of adversarial attacks on the algorithms and data; this number balloons if we were to incorporate papers covering non-adversarial failure modes. The spate of papers has made it difficult for ML practitioners, let alone engineers, lawyers, and policymakers, to keep up with the attacks against and defenses of ML systems. However, as these systems become more pervasive, the need to understand how they fail, whether by the hand of an adversary or due to the inherent design of a system, will only become more pressing. In order to equip software developers, security incident responders, lawyers, and policy makers with a common vernacular to talk about this problem, we developed a framework to classify failures into \"Intentional failures\" where the failure is caused by an active adversary attempting to subvert the system to attain her goals; and \"Unintentional failures\" where the failure is because an ML system produces an inherently unsafe outcome. After developing the initial version of the taxonomy last year, we worked with security and ML teams across Microsoft, 23 external partners, standards organization, and governments to understand how stakeholders would use our framework. Throughout the paper, we attempt to highlight how machine learning failure modes are meaningfully different from traditional software failures from a technology and policy perspective.","url_abs":"https://arxiv.org/abs/1911.11034v1","url_pdf":"https://arxiv.org/pdf/1911.11034v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"failure-modes-in-machine-learning-systems","repo_url":"https://github.com/fclesio/ml-adversarial","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"none","reach":{"status":"ok","spdx":"CC0-1.0"}},{"paper_slug":"failure-modes-in-machine-learning-systems","repo_url":"https://github.com/fclesio/pycon-africa-2020-security-ml","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"none","reach":{"status":"ok","spdx":"CC0-1.0"}}],"tasks":[{"task_slug":"machine-learning","task_name":"BIG-bench Machine Learning"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/1911.11034","atlas_url":"https://app.syntology.ai/?focus=1911.11034","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1911.11034"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/fclesio/ml-adversarial","reach":{"status":"ok","spdx":"CC0-1.0"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/fclesio/pycon-africa-2020-security-ml","reach":{"status":"ok","spdx":"CC0-1.0"}}],"summary":{"ran":6},"by_repo_kind":{"listed":{"samples":6,"ran":6,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"cf56c05b55d4a5c1","entry":"generate_backdoor_poisoning","repo":"fclesio/ml-adversarial","repo_kind":"listed","path":"src/backdoor-modelo/generate-dataset.py","file_url":"https://github.com/fclesio/ml-adversarial/blob/HEAD/src/backdoor-modelo/generate-dataset.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"CC0-1.0","inline_ok":true,"mcp_get_code":{"code_sha256":"cf56c05b55d4a5c1"}},{"code_sha256_prefix":"1e915c8a67939f94","entry":"generate_dataset","repo":"fclesio/ml-adversarial","repo_kind":"listed","path":"src/backdoor-modelo/generate-dataset.py","file_url":"https://github.com/fclesio/ml-adversarial/blob/HEAD/src/backdoor-modelo/generate-dataset.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"CC0-1.0","inline_ok":true,"mcp_get_code":{"code_sha256":"1e915c8a67939f94"}},{"code_sha256_prefix":"a212a1c8c7fe27d6","entry":"get_features_and_labels","repo":"fclesio/ml-adversarial","repo_kind":"listed","path":"src/ataque-cadeia-insumo/model-training.py","file_url":"https://github.com/fclesio/ml-adversarial/blob/HEAD/src/ataque-cadeia-insumo/model-training.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"CC0-1.0","inline_ok":true,"mcp_get_code":{"code_sha256":"a212a1c8c7fe27d6"}},{"code_sha256_prefix":"f65f9deadec99336","entry":"get_features_and_labels","repo":"fclesio/ml-adversarial","repo_kind":"listed","path":"src/envenenamento-modelo/model-training.py","file_url":"https://github.com/fclesio/ml-adversarial/blob/HEAD/src/envenenamento-modelo/model-training.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"CC0-1.0","inline_ok":true,"mcp_get_code":{"code_sha256":"f65f9deadec99336"}},{"code_sha256_prefix":"00dded8818210f1e","entry":"load_data","repo":"fclesio/ml-adversarial","repo_kind":"listed","path":"src/envenenamento-modelo/model-training.py","file_url":"https://github.com/fclesio/ml-adversarial/blob/HEAD/src/envenenamento-modelo/model-training.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"CC0-1.0","inline_ok":true,"mcp_get_code":{"code_sha256":"00dded8818210f1e"}},{"code_sha256_prefix":"6fb179dc712af61e","entry":"poison_data","repo":"fclesio/ml-adversarial","repo_kind":"listed","path":"src/envenenamento-modelo/poison-dataset.py","file_url":"https://github.com/fclesio/ml-adversarial/blob/HEAD/src/envenenamento-modelo/poison-dataset.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"CC0-1.0","inline_ok":true,"mcp_get_code":{"code_sha256":"6fb179dc712af61e"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}