paper-with-me

Papers

Evaluating the Cybersecurity Risk of Real World, Machine Learning Production Systems

2021-07-05 · Ron Bitton, Nadav Maman, Inderjeet Singh, Satoru Momiyama, Yuval Elovici, Asaf Shabtai

Although cyberattacks on machine learning (ML) production systems can be harmful, today, security practitioners are ill equipped, lacking methodologies and tactical tools that would allow them to analyze the security risks of their ML-based systems. In this paper, we performed a comprehensive threat analysis of ML production systems. In this analysis, we follow the ontology presented by NIST for evaluating enterprise network security risk and apply it to ML-based production systems. Specifically, we (1) enumerate the assets of a typical ML production system, (2) describe the threat model (i.e., potential adversaries, their capabilities, and their main goal), (3) identify the various threats to ML systems, and (4) review a large number of attacks, demonstrated in previous studies, which can realize these threats. In addition, to quantify the risk of adversarial machine learning (AML) threat, we introduce a novel scoring system, which assign a severity score to different AML attacks. The proposed scoring system utilizes the analytic hierarchy process (AHP) for ranking, with the assistance of security experts, various attributes of the attacks. Finally, we developed an extension to the MulVAL attack graph generation and analysis framework to incorporate cyberattacks on ML production systems. Using the extension, security practitioners can apply attack graph analysis methods in environments that include ML components; thus, providing security practitioners with a methodological and practical tool for evaluating the impact and quantifying the risk of a cyberattack targeting an ML production system.

📄 PDF Abstract BibTeX arXiv:2107.01806

Code (0)

등록된 구현이 없습니다.

Tasks

BIG-bench Machine LearningGraph Generation

Similar Papers 제목 키워드 기반

LLM Cyber Evaluations Don't Capture Real-World Risk

2025-01-31 · Kamilė Lukošiūtė, Adam Swanda

Large language models (LLMs) are demonstrating increasing prowess in cybersecurity applications, creating creating inherent risks alongside their potential for strengthening defenses. In this position paper, we argue tha…

Large Language Models in Cybersecurity: State-of-the-Art

2024-01-30 · Farzad Nourmohammadzadeh Motlagh, Mehrdad Hajizadeh, Mehryar Majd, Pejman Najafi 외

The rise of Large Language Models (LLMs) has revolutionized our comprehension of intelligence bringing us closer to Artificial Intelligence. Since their introduction, researchers have actively explored the applications o…

Supply Chain Trust Decline: Cybersecurity Risks and Corporate Trade Credit

2024-05-08 · China Industrial Economy 2024 5 · GENG Yong, XIANG Xiao-jian, WAN Pan-bing

: With the rapid expansion of cyberspace and the fast development of information technology, cyberattacks have become increasingly commonplace. According to the survey of Cybersecurity Ventures, a world-renowned netw…

FRAME : Comprehensive Risk Assessment Framework for Adversarial Machine Learning Threats

2025-08-24 · Avishag Shapira, Simon Shigol, Asaf Shabtai arxiv

The widespread adoption of machine learning (ML) systems increased attention to their security and emergence of adversarial machine learning (AML) techniques that exploit fundamental vulnerabilities in ML systems, creati…

Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models

2024-08-15 · Andy K. Zhang, Neil Perry, Riya Dulepet, Joey Ji 외

Language Model (LM) agents for cybersecurity that are capable of autonomously identifying vulnerabilities and executing exploits have potential to cause real-world impact. Policymakers, model providers, and researchers i…