Pith. sign in

REVIEW 1 cited by

Towards more Practical Threat Models in Artificial Intelligence Security

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2311.09994 v2 pith:XFIUMF7V submitted 2023-11-16 cs.CR cs.AI

classification cs.CRcs.AI
keywords modelssecuritythreatartificialintelligencepracticalpracticeresearch
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Recent works have identified a gap between research and practice in artificial intelligence security: threats studied in academia do not always reflect the practical use and security risks of AI. For example, while models are often studied in isolation, they form part of larger ML pipelines in practice. Recent works also brought forward that adversarial manipulations introduced by academic attacks are impractical. We take a first step towards describing the full extent of this disparity. To this end, we revisit the threat models of the six most studied attacks in AI security research and match them to AI usage in practice via a survey with 271 industrial practitioners. On the one hand, we find that all existing threat models are indeed applicable. On the other hand, there are significant mismatches: research is often too generous with the attacker, assuming access to information not frequently available in real-world settings. Our paper is thus a call for action to study more practical threat models in artificial intelligence security.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Countering Backdoor Attacks in Image Recognition: A Survey and Evaluation of Mitigation Strategies

    cs.CR 2024-11 conditional novelty 4.0 of 10

    A large benchmark of 16 backdoor mitigation methods shows high performance variability across settings, with only FT-SAM and SAU outperforming their baselines, and most newer methods failing to beat FP and FT.

Pith tools