An Adversarial Strategic Game for Machine Learning as a Service using System Features

Guoxin Sun (University of Melbourne), Tansu Alpcan (University of Melbourne), Seyit Camtepe (CSIRO Data61), Andrew C. Cullen (University of Melbourne), Benjamin I.P. Rubinstein (University of Melbourne)

Abstract

Machine-learning-as-a-service (MLaaS) dramatically decreases the barrier of entry to machine learning through accessible, externally trained model building and deployment. However, numerous studies have shown that MLaaS models are vulnerable to adversarial attacks, which can alter input data with small perturbations and deceive the underlying machine learning algorithms. In this paper, we propose a novel approach for detecting and mitigating adversarial attacks in MLaaS. Our approach leverages previously overlooked system-level features in combination with data-driven methods to detect the generation process of adversarial examples. To guide the mitigation process, we model the dynamic interactions between an adaptive adversary, an imperfect anomaly detector, and a broader defensive system as a non-cooperative strategic game with imperfect information. We use experimental data from a realistic small-scale MLaaS ecosystem to construct the game components, such as players' utilities and detection accuracy. Our experimental results indicate that an adversarial attack against MLaaS defended by our method requires up to six times more cloud service accounts compared to other state-of-the-art frameworks. These promising results demonstrate the importance of considering realistic system settings when developing and evaluating adversarial attacks and defenses.