Vulnerabilities of Connectionist AI Applications: Evaluation and Defense.

IT security adversarial attack artificial intelligence certification interpretability neural network poisoning attack

Journal

Frontiers in big data
ISSN: 2624-909X
Titre abrégé: Front Big Data
Pays: Switzerland
ID NLM: 101770603

Informations de publication

Date de publication:
2020
Historique:
received: 20 03 2020
accepted: 10 06 2020
entrez: 11 3 2021
pubmed: 12 3 2021
medline: 12 3 2021
Statut: epublish

Résumé

This article deals with the IT security of connectionist artificial intelligence (AI) applications, focusing on threats to integrity, one of the three IT security goals. Such threats are for instance most relevant in prominent AI computer vision applications. In order to present a holistic view on the IT security goal integrity, many additional aspects, such as interpretability, robustness and documentation are taken into account. A comprehensive list of threats and possible mitigations is presented by reviewing the state-of-the-art literature. AI-specific vulnerabilities, such as adversarial attacks and poisoning attacks are discussed in detail, together with key factors underlying them. Additionally and in contrast to former reviews, the whole AI life cycle is analyzed with respect to vulnerabilities, including the planning, data acquisition, training, evaluation and operation phases. The discussion of mitigations is likewise not restricted to the level of the AI system itself but rather advocates viewing AI systems in the context of their life cycles and their embeddings in larger IT infrastructures and hardware devices. Based on this and the observation that adaptive attackers may circumvent any single published AI-specific defense to date, the article concludes that single protective measures are not sufficient but rather multiple measures on different levels have to be combined to achieve a minimum level of IT security for AI applications.

Identifiants

pubmed: 33693396
doi: 10.3389/fdata.2020.00023
pmc: PMC7931957
doi:

Types de publication

Journal Article Review

Langues

eng

Pagination

23

Informations de copyright

Copyright © 2020 Berghoff, Neu and von Twickel.

Références

Nat Mach Intell. 2020 Jan;2(1):56-67
pubmed: 32607472
Bull Math Biol. 1990;52(1-2):99-115; discussion 73-97
pubmed: 2185863
Neural Netw. 2019 May;113:54-71
pubmed: 30780045
Nat Rev Neurosci. 2001 Dec;2(12):920-6
pubmed: 11733799
J Exp Psychol Hum Percept Perform. 2015 Aug;41(4):929-39
pubmed: 25915074
Network. 2002 May;13(2):195-216
pubmed: 12061420
Atten Percept Psychophys. 2013 Jul;75(5):830-4
pubmed: 23757046
Learn Mem. 2005 Jul-Aug;12(4):361-6
pubmed: 16027179
Nat Commun. 2019 Mar 11;10(1):1096
pubmed: 30858366
PLoS One. 2015 Jul 10;10(7):e0130140
pubmed: 26161953
Front Psychol. 2018 Nov 13;9:2190
pubmed: 30483196

Auteurs

Christian Berghoff (C)

Federal Office for Information Security, Bonn, Germany.

Matthias Neu (M)

Federal Office for Information Security, Bonn, Germany.

Arndt von Twickel (A)

Federal Office for Information Security, Bonn, Germany.

Classifications MeSH