<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Keynote: An Optimal Control View of Adversarial Machine Learning</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Xiaojin Zhu</string-name>
        </contrib>
      </contrib-group>
      <abstract>
        <p />
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>Test-time adversarial examples, training set poisoning,
reward shaping, etc.: these attacks as studied in adversarial
machine learning have one thing in common: the adversary
literally wants to control a machine learning system. In this talk,
we will develop this connection to control theory. The
resulting view allows more clarity into adversarial learning, and
opens up promising research directions.</p>
      <p>X. Zhu is with the Department of Computer Science,
University of Wisconsin-Madison, WI, USA. e-mail:
jerryzhu@cs.wisc.edu
Copyright ⃝c by the paper’s authors. Copying permitted for private
and academic purposes. In: Joseph Collins, Prithviraj Dasgupta,
Ranjeev Mittu (eds.): Proceedings of the AAAI Fall 2018
Symposium on Adversary-Aware Learning Techniques and Trends in
Cybersecurity, Arlington, VA, USA, 18-19 October, 2018, published
at http://ceur-ws.org</p>
    </sec>
  </body>
  <back>
    <ref-list />
  </back>
</article>