REVIEW 3 cited by
A Research Agenda: Dynamic Models to Defend Against Correlated Attacks
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
In this article I describe a research agenda for securing machine learning models against adversarial inputs at test time. This article does not present results but instead shares some of my thoughts about where I think that the field needs to go. Modern machine learning works very well on I.I.D. data: data for which each example is drawn {\em independently} and for which the distribution generating each example is {\em identical}. When these assumptions are relaxed, modern machine learning can perform very poorly. When machine learning is used in contexts where security is a concern, it is desirable to design models that perform well even when the input is designed by a malicious adversary. So far most research in this direction has focused on an adversary who violates the {\em identical} assumption, and imposes some kind of restricted worst-case distribution shift. I argue that machine learning security researchers should also address the problem of relaxing the {\em independence} assumption and that current strategies designed for robustness to distribution shift will not do so. I recommend {\em dynamic models} that change each time they are run as a potential solution path to this problem, and show an example of a simple attack using correlated data that can be mitigated by a simple dynamic defense. This is not intended as a real-world security measure, but as a recommendation to explore this research direction and develop more realistic defenses.
Forward citations
Cited by 3 Pith papers
-
Testing Robustness Against Unforeseen Adversaries
ImageNet-UA, a six-attack benchmark with four new attacks, shows L-infinity robustness does not transfer to unforeseen distortions and that L2 training and AugMix generalize better.
-
DYNASHIELD: A Black-Box Moving Target Defense for LLMs via Dynamic Decoding Customization
Randomizing decoding hyperparameters and system prompts per query lowers jailbreak attack success on five 7B LLMs, from 74% down to 0% in the best reported case, but the evaluation uses the same benchmark that selecte...
-
Out of Control -- Why Alignment Needs Formal Control Theory (and an Alignment Control Stack)
A position paper proposing that AI alignment adopt formal optimal control and a ten-layer Alignment Control Stack for organizing and interoperating control interventions.
Discussion (0). Continue with ORCID to comment.