Defence Against the Dark Arts: Adversarial ML


Security and Privacy issues need no introduction. But how exactly is this affecting the field of Machine Learning? This is what this talk will cover. We first expose the attack surface of systems deploying machine learning. We then describe how an attacker may force models to make wrong predictions with very little information about the victim. One such attack can be biometric recognition where fake biometric traits may be exploited to impersonate a legitimate user. We demonstrate that these attacks are practical against existing machine learning as a service platform. Towards the end, we will discuss current research to defend models from such attacks.

