<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Attacks on Machine Learning: Lurking Danger for Accountability</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Katja Auernhammer</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Ramin Tavakoli Kolagari</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Markus Zoppelt</string-name>
          <email>markus.zoppeltg@th-nuernberg.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Nuremberg Institute of Technology, Faculty of Computer Science Hohfederstrasse 40 Nuremberg</institution>
          ,
          <addr-line>90489</addr-line>
          ,
          <country country="DE">Germany</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>It is well-known that there is no safety without security. That being said, a sound investigation of security breaches on Machine Learning (ML) is a prerequisite for any safety concerns. Since attacks on ML systems and their impact on the security goals threaten the safety of an ML system, we discuss the impact attacks have on the ML models' security goals, which are rarely considered in published scientific papers. The contribution of this paper is a non-exhaustive list of published attacks on ML models and a categorization of attacks according to their phase (training, after-training) and their impact on security goals. Based on our categorization we show that not all security goals have yet been considered in the literature, either because they were ignored or there are no publications on attacks targeting those goals specifically, and that some are difficult to assess, such as accountability. This is probably due to some ML models being a black box.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>During the last few years scientists and researchers have
published a variety of different attacks on Machine Learning
(ML) systems. However, the papers only rarely mention
security goals—such as integrity, availability, confidentiality,
reliability, authenticity, and accountability—that are
endangered by these attacks. Even if a paper explicitly mentions
the violation of a security goal it is not clear if the breach
refers to the whole system in which the ML model is
embedded or rather the ML model itself or parts of it.</p>
      <p>The contribution of this paper is a non-exhaustive list
of published attacks on ML and a derivation of different
groups of attacks. We further elaborate on the breaches of
known security goals (integrity, availability, confidentiality,
etc.) caused by the listed attacks to justify our categorization
and show the security goals mentioned in published papers
about attacks on ML. Our categorization clarifies that there
are some security goals, such as accountability, which are
yet difficult to evaluate due to the complex operations within
ML models.
The six main security goals as described in [21] are
summarized as follows:
Copyright held by authors.</p>
      <p>Confidentiality ensures that private or confidential
information is not made available or disclosed to unauthorized
users, and that users can control (or influence) what
information related to them may be collected, used, and
to whom it is disclosed. Confidentiality is often
implemented through cryptography / encryption.</p>
      <p>Integrity ensures that information is not changed
(modified) or destroyed unauthorizedly. Integrity can be
compromised even if the information or system produces the
correct output.</p>
      <p>Availability ensures that a system works promptly,
service is not denied to authorized users, and access to and
use of information is timely and reliable.</p>
      <p>Authenticity is the characteristic of being genuine
and verifiable and trustworthy. Authenticity is ensured
through authentication processes that verify whether users
are who they say they are (entity authenticity).
Authenticity is often enabled through cryptography / cryptographic
signatures.</p>
      <p>Reliability is the property of a system such that reliance
can be justifiably placed on the service it delivers, i.e., the
system adheres to the specification it was engineered to
address.</p>
      <p>Accountability refers to the requirements for actions of
an entity to be traced uniquely to that entity (e.g.,
nonrepudiation of a communication that took place).
Accountability allows a certain degree of transparency to
what happened when and what was performed by whom.</p>
    </sec>
    <sec id="sec-2">
      <title>Attacks on Machine Learning Algorithms</title>
      <p>Important criteria that influence the applicability of certain
attacks on ML models at this level of detail are the
learning type (supervised, unsupervised, reinforcement learning)
and if the algorithm undergoes lifelong learning. Different
attacks are designed to target combinations of different
criteria. The implications to the security goals of the ML model
are equivalent to the security goals corresponding to the
categorization of the attack.</p>
      <p>In Table 1 the first column names the ML algorithm in
alphabetical order, followed by the learning type and whether
the model is capable of lifelong learning or not. Lifelong
learning is a criterion that is often ignored by researchers
Table 1: Published attacks on ML categorized by ML algorithms. The listed ML algorithms are derived from the publications
of the attacks, therefore, there might be attacks aimed at, e.g., neural networks in general but also attacks on specific sub-types
of neural networks, e.g., convolutional neural networks. The columns “Learning Type” and “Lifelong Learning” do not solely
refer to what the algorithm is capable of but to the premises the ML algorithm must meet to render the attack effective
ML Algorithm Learning Type Lifelong L. Attack
Complete-linkage Hierarchical Clustering Unsupervised No Poisoning Attack [9]
Single-Linkage Hierarchical Clustering Unsupervised No Poisoning Attack [13]
Obfuscation Attack [13, 14]
Decision Tree/Random Forest Supervised Yes/No Poisoning Attack [46]
No Path-finding Attack [72]</p>
      <p>Model Inversion [26]
Ateniese et al. Attack [4]
Adversarial Examples [31, 52, 66]
Hidden Markov Model Supervised No Ateniese et al. Attack [4]
k-Nearest Neighbors Supervised Yes/No Poisoning Attack [46]
No Adversarial Examples [31]
k-Means Clustering Unsupervised No Ateniese et al. Attack [4]
Linear Regression Supervised Yes/No Poisoning Attack [8, 35, 41]
No Model Inversion [27]</p>
      <p>Lowd-Meek Attack [44, 72]
Logistic Regression Supervised No Equation-solving Attack [49]
Hyperparameter Stealing [73]
Adversarial Examples [52, 70, 71]
Multi-class Logistic Regression Supervised No Equation-solving Attack [49]
Maximum Entropy Models Supervised No Lowd-Meek Attack [44]
Naive Bayes Supervised No Classifier Evasion [3, 22]
Lowd-Meek Attack [44]
Neural Network Reinforcement Unclear Strategically-timed Attack [40]
Learning Enchanting Attack [40]</p>
      <p>Adversarial Examples [33, 40]
Neural Network Supervised No Model Inversion [26]
Membership Inference [63]
Hyperparameter Stealing Attack [73]
Ateniese et al. Attack [4]
Adversarial Examples [29, 31, 45, 52, 62, 70]
Trojan Trigger [43]
Multi-layer Perceptron Supervised Yes/No Poisoning Attack [46]
No Equation-solving Attack [49]</p>
      <p>Ateniese et al. Attack [4]
Convolutional Neural Network Supervised No Side-channel Attack [74]
Training Data Extraction [18]
Adversarial Examples [50, 52, 70]
Recurrent Neural Network Supervised No Training Data Extraction [18]
Classifier Evasion [3]
Adversarial Examples [57]
Support Vector Machine Supervised Yes/No Poisoning Attack [12, 46]
Adversarial Label Flips [76, 77]
No Hyperparameter Stealing [73]</p>
      <p>Lowd-Meek Attack [44, 72]
Ateniese et al. Attack [4]
Evasion Attack [3, 24, 30, 61, 66]
Feature Deletion [28]
Adversarial Examples [31, 52, 66, 71]
or at least not explicitly mentioned in papers. We
complemented this information wherever necessary according to
the definition in common text books. There are four
possible values for lifelong learning: Yes, No, Yes/No (when both
can be the case) and unclear (when we simply do not know).</p>
      <p>In the last column we list the attacks with corresponding
literature.</p>
      <p>We also identified attacks that are employable against
several ML algorithms. Attacks we consider applicable to
systems regardless of the ML algorithm, learning type, and
lifelong learning capability are, for example, poisoning attacks
[8, 46] as these attacks do not focus on the model but the
training data; therefore, poisoning attacks are considered
independent of the ML algorithm.</p>
      <p>Another group of attacks that tamper with data fed into
the ML model, and thus are applicable on a wide range of
different ML algorithms, are adversarial examples [5, 6, 17,
34, 51, 59], evasion attacks [23, 78], and feature deletion
attacks. These attacks exploit weaknesses in the ML model
without changing the model itself by simply perturbing the
input to falsify the output.</p>
      <p>Shokri et al. [63] claim their attack, membership
inference, to be generic, although they only apply it to
classification algorithms. We also think the attack is only applicable to
ML algorithms that are not capable of lifelong learning, as
membership inference relies on computing multiple inputs
via the ML model to extract information about the training
data. If the model adapts with every given input, this
approach can be aggravated.</p>
    </sec>
    <sec id="sec-3">
      <title>Categorization of ML Attacks with Regard to</title>
    </sec>
    <sec id="sec-4">
      <title>Security Goals</title>
      <p>In software security it is well-established to distinguish
between attacks with regard to their effects on security goals
(see Section “Security Goals”). The attacks described in
Table 2 affect one or more security goals of a system (here:
an ML component). A categorization of the published
attacks according to security goals compiles an overview of
clusters of similar attack scenarios as well as of missing but
expected attack clusters. These gaps in the categorization of
attacks may result from unknown publications about attacks
on ML components, from unpublished attacks or attacks that
have not yet been executed but which are all conceivable and
therefore executable in principle. Therefore, these gaps in
the categorization are particularly revealing.</p>
      <p>Of particular relevance for the categorization of attacks
developed here is the violation of security goals, which
affect the ML component as a whole. Thus, the violation of the
integrity for an ML component means that the ML
component itself is changed (in some form). In the publications on
the attacks on ML components analyzed here (and also listed
in Table 2), statements are partly made on the violations of
the security goals, but these sometimes refer (only) to
partial areas of an attack. Thus, the attack adversarial examples
[69], which manipulates data fed into the model, targets—
according to the authors—integrity, namely the integrity of
the input data; as the integrity of the ML model itself is not
attacked because it has not been changed, it is not
categorized in Table 2 under integrity.</p>
      <p>Table 2 shows our mapping of the analyzed attacks listed
in Table 1 to the six security goals described in the
Security Goals section. While Table 1 focused on the ML
algorithms Table 2 brings the attacks into focus. The assignment
in Table 2 is based on the description of the attacks in the
respective publications. In the table, an “X” indicates which
security goal (related to the ML component as a whole) is
affected by which attack.</p>
      <p>In addition, many attacks have been published that relate
to pre- and post-processing units of ML components (their
environment). These attacks do not differ from those on
traditional software, therefore they are not described in this
paper.</p>
      <p>An obvious peculiarity of ML components compared to
traditional software is their training, so there are two
essential phases in their life cycle: the training phase (T) and the
deployment phase that we prefer to call the after-training
phase (A), as this also considers lifelong learning ML
algorithms, which are trained with every input even after
deployment. This continuous learning process makes attacks
in deployment time possible, which are also applicable in
training time (such as poisoning attacks [60]) and, on the
other hand, disables the applicability of attacks that require
a fixed target model (e.g., model inversion [26]).</p>
      <p>Unlike previous research (e.g., [7, 55]) we do not consider
whether an attack is targeted, whether the opponent causes a
certain wrong output or not, whether a wrong output is
generated, or whether the opponent has white box or black box
knowledge. At this point we also do not distinguish between
different types of learning (supervised, unsupervised,
reinforcement learning). Considering all these kinds of criterion,
a blurred categorization would be created that contradicts a
clear distinction between attacks. Instead, we propose
considering the above criteria within each of our main groups in
order to add further dimensions and form sub-groups. This
is not within the scope of this paper, although we consider
the learning type in Table 1, which can be used as a starting
point for further investigations.</p>
      <p>By analyzing the security goals that are breached by the
attacks and the time the attack takes place, we can create
different categories of attacks. The names of the categories
are derived from whether the attack takes place during
training time (T) or after-training time (A) followed by a dash
(-) and the first one or two letters of the main security goals,
which are breached by the attacks. Grey “X”s indicate the
main assignments of attacks to security goals.</p>
      <p>First of all, it is noticeable that all attacks at training time
affect both integrity and reliability. This also makes sense
immediately: if only the integrity was corrupted during
training time, the system could be corrected conform to the
specification via the existing reliability. If only the reliability was
corrupted, the unchanged behavior would result in a
difference to the specification, which would result in a correction
of the specification. Only a simultaneous attack on both
security goals can therefore be successful during the training
phase. Confidentiality is not a main security goal for attacks
during the training phase, but most of the identified attacks
have attacked the confidentiality as well. However,
successful attacks during the training phase that relate exclusively to
integrity and reliability would also be conceivable.
Attacking the security goal availability makes no sense during the
training phase.</p>
      <p>Attacks on integrity and reliability during the deployment
phase are theoretically meaningful and have been published
pertinently. They represent the mirroring of attacks on
integrity and reliability from the training phase. An essential
group with a particularly large number of published attacks
in the deployment phase refers to confidentiality. The fact
that these attacks are often accompanied by restrictions in
availability is rather a side effect than a main aspect. A
category of attacks on ML components that mainly refers to
availability (think of DoS attacks on traditional software)
makes little sense in theory and has not been published. The
frequently cited adversarial examples attack group is among
others in the category of reliability attacks during the
deployment phase; typically, integrity is not corrupted because
the ML components themselves are not modified.</p>
      <p>The lack of assignments to the security goals
authenticity and accountability are also particularly informative. In
our research we could not find any attacks on these
security goals of the ML components. Authenticity is usually
implemented in the environmental components surrounding
an ML component. This will probably change in the future,
however, when comprehensive tasks will be implemented in
a network of ML components and it becomes necessary to
establish the ML components as mission-critical
communication partners. Accountability of ML is considered—even
in the community of ML experts—to be mostly
inaccessible (especially with the so-called black box ML components
such as deep neural networks), because these components
cannot be read like traditional software and cannot be
semantically deduced from the structure. Nevertheless, we
believe that a new field of attacks on ML components will
open up in this field in the future because initiatives such
as eXplainable AI (layer-wise relevance propagation [16],
Black Box Explanations through Transparent
Approximations (BETA) [37], LIME [58], Generalized Additive Model
(GAM) [19], etc.) and the political demand for
comprehensible AI decisions will ensure greater comprehensibility in the
area of the black box ML, which will ultimately also help
the attackers.</p>
    </sec>
    <sec id="sec-5">
      <title>The Peculiarity of Accountability</title>
      <p>It is yet unclear, how the concept of accountability applies
to ML. Accountability in traditional software engineering
means an action can always be retraced to the entity
performing the action. An entity is usually a human or a digital
agent, however, the definition of an entity is not clear in the
field of ML. An entity could be an input feature which leads
to a certain output of the ML model (this meets the
definition made by Papernot et al. [56]). An entity could also be
an element within in the ML model, e.g., each single neuron
within a neural network, which makes its own decision that
influences the final output of the model. From a different
point of view even the software developer could be
considered the entity.</p>
      <p>The entity, which can not deny an action, is ultimately
relevant in a legal context, namely in case of finding the party
liable for a specific action. It is not relevant, however, how
a single element of an algorithm contributed to the system’s
decision, but whether the wrong decision was caused due to
faulty training, biases in the training data or malicious
attacks.</p>
      <p>We find that there is no clear definition of
accountability and that it is difficult to transfer existing definitions to
the field of ML. In order to guarantee accountability at all,
changes in the system, e.g., in traditional software this could
be changes in the database, must be recorded. Without a
form of audit that promises some form of tracing,
accountability cannot be broken, because the goal was not even
reached in the first place. With a ML system, the changes
within a system do not necessarily have to be recorded.
Rather the decisions of the system or of parts of the system
should be made assignable to a distinct entity.</p>
      <p>In the context of ML, a distinction between accountability
and liability should be considered. Both focus on retracing
an action to an entity. Liability, however, concentrates on the
assignment of blame or debt relief of individual entities and
is also possible without an audit of the actions and decision
made by inner components within the ML algorithm. For
liability it is sufficient to record the final decision of the ML
system solely.</p>
      <p>Accountability, on the other hand, is only possible by
logging the internal processes. The definition of an “entity”,
however, is still unclear. Furthermore, logging requires a
certain understanding of the model, which is difficult up until
now. However, if ML algorithms become comprehensible in
the future, accountability could be achievable and this also
means that accountability—as a security goal—can be
broken by attackers.</p>
      <p>Assume it will be possible to identify which nodes in
a neural network are responsible for a particular decision.
E.g., we know which nodes in an image recognition
system are responsible for detecting certain objects, such as
stop signs. If these nodes are regarded as entities, they can
be made accountable for their decisions. Accountability
allows ML algorithms to be developed and validated more
efficiently maybe even to the point where they become similar
to the code of traditional software development. This is
desirable in any case, as it greatly simplifies development and
troubleshooting. If this knowledge about accountability is
leaked, adversaries can also take advantage of it and launch
more targeted attacks, which might ultimately also target
accountability. A breach in accountability will most likely be
the first step to sophisticated attacks that violate other
security goals as well.</p>
      <p>It is unclear what types of attacks might be possible once
ML models can be fully explained to humans, though.</p>
    </sec>
    <sec id="sec-6">
      <title>Related Work</title>
      <p>Barreno et al. [7] give relevant properties they consider
important when conducting attacks on ML. The properties are
grouped into three categories: the influence of the attack on
the target system, the specificity (targeted or untargeted) and
the security violation (integrity, availability). Their paper
focuses mostly on countermeasures against attacks. Papernot
et al. [55] also review attacks and distinguish them into black
box and white box attacks. They focus on attacks on
classification algorithms and list theoretical countermeasures. Liu
et al. [42] also discuss different attacks and propose
interesting points to consider in future research. Biggio et al. [15]
take a different view on attacks on ML. They focus on how
the field has developed during the years since its first
mention in 2004. They also review published countermeasures.</p>
      <p>Alabdulmohsin et al. [2] sort attacks into causative or
exploratory attacks. A survey of attacks against deep learning
in computer vision was conducted by Akhtar and Mian [1].
They list several published countermeasures against
adversarial examples. Laskov and Kloft [38] propose a
“framework for quantitative security analysis of ML models”.</p>
    </sec>
    <sec id="sec-7">
      <title>Conclusion</title>
      <p>In this paper we give an overview of the current
state-of-theart ML algorithms and their respective attacks. This list is
especially interesting when considering some of the more
critical fields ML is used in, such as autonomous driving.
Autonomous driving uses ML models in safety-critical
applications. Ignoring known attacks on pertinent ML algorithms is
hazardous as human life is at stake. Likewise, regular
software development, security by design has to be applied to
the development of ML algorithms as well.</p>
      <p>We also propose a classification of published attacks on
ML models based on security goals and life cycle phase.</p>
      <p>Our research shows that accountability is not covered by
literature as there have not yet been any attacks published.
This is probably due to the fact that accountability for ML
is difficult to attack as ML models are yet beyond human
understanding and, therefore, the security goal is not
compulsory.</p>
      <p>Although, there are already some papers working on a
solution to improve comprehensibility of ML models, we
think there is still a long way to go until humans are able
to completely understand ML models. If accountability can
be guaranteed for all kinds of ML models this will enable a
wide range of new yet unknown attacks.</p>
      <p>Further research will elaborate the implications of
vulnerable ML models. It will also discuss whether and how the
security goal accountability can be transferred to the field
of ML and if proper accountability of ML models has to be
considered in liability claims.</p>
    </sec>
    <sec id="sec-8">
      <title>Acknowledgement</title>
      <p>Katja Auernhammer and Markus Zoppelt were supported by
the BayWISS Consortium Digitization.
[14]
[15]
[16]
[17]
[18]
[19]
[20]
[21]
[22]
[23]
[24]
[25]
[26]
[27]
[28]
[29]
[30]
[32]
[33]
[34]
[35]
[36]
[37]</p>
      <p>
        Alhussein Fawzi, Seyed Mohsen Moosavi-Dezfooli, and
Pascal Frossard. “The Robustness of Deep Networks: A
Geometrical Perspective”. In: IEEE Signal Processing
Magazine 34.6 (2017), pp. 50–62. ISSN: 10535888. DOI: 10 .
        <xref ref-type="bibr" rid="ref38">1109/MSP.2017</xref>
        .2740965.
      </p>
      <p>Matt Fredrikson, Somesh Jha, and Thomas Ristenpart.
“Model Inversion Attacks that Exploit Confidence
Information and Basic Countermeasures”. In: Proceedings of the
22nd ACM SIGSAC Conference on Computer and
Communications Security - CCS ’15. New York, USA: ACM
Press, 2015, pp. 1322–1333. ISBN: 9781450338325. DOI:
10.1145/2810103.2813677.</p>
      <p>Matt Fredrikson, Eric Lantz, Somesh Jha, Simon Lin, David
Page, and Thomas Ristenpart. “Privacy in
Pharmacogenetics: An End-to-End Case Study of Personalized Warfarin
Dosing”. In: Proceedings of the 23rd USENIX Security
Symposium (2014), pp. 17–32.</p>
      <p>
        Amir Globerson and Sam Roweis. “Nightmare at test time:
robust learning by feature deletion”. In: Proceedings of the
23rd international conference on Machine learning (2006),
pp. 353–360. DOI: 10.1145/1143844.1143889.
Abigail Graese, Andras Rozsa, and Terrance E. Boult.
“Assessing threat of adversarial examples on deep
neural networks”.
        <xref ref-type="bibr" rid="ref49">In: Proceedings - 2016</xref>
        15th IEEE
International Conference on Machine Learn
        <xref ref-type="bibr" rid="ref49">ing and Applications,
ICMLA 2016</xref>
        (2017), pp. 69–74. DOI: 10.
        <xref ref-type="bibr" rid="ref57">1109/ICMLA.
2016</xref>
        .44. arXiv: 1610.04256.
      </p>
      <p>Yi Han and Benjamin I. P. Rubinstein. “Adequacy of the
Gradient-Descent Method for Classifier Evasion Attacks”.
In: (2017). arXiv: 1704.01704.</p>
      <p>Briland Hitaj, Giuseppe Ateniese, and Fernando
PerezCruz. “Deep Models Under the GAN: Information
Leakage from Collaborative Deep Learning”. In: Proceedings
of the 2017 ACM SIGSAC Conference on Computer and
Communications Security - CCS ’17. New York, USA:
ACM Press, 2017, pp. 603–618. ISBN: 9781450349468.
DOI: 10 . 1145 / 3133956 . 3134012. arXiv: 1702 .
07464.</p>
      <p>
        Sandy Huang, Nicolas Papernot, Ian Goodfellow, Yan
Duan, and Pieter Abbeel. “Adversarial Attacks on Neural
Network Policies”. In: (Feb. 2017). arXiv: 1702.02284.
Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy
Lin. “Query-Efficient Black-box Adversarial Examples”.
In: (Dec. 2017).
        <xref ref-type="bibr" rid="ref19">arXiv: 1712</xref>
        .07113.
      </p>
      <p>
        Matthew Jagielski, Alina Oprea, Battista Biggio, Chang
Liu, Cristina Nita-Rotaru, and Bo Li. “Manipulating
Machine Learning: Poisoning Attacks and Countermeasures
for Regression Learn
        <xref ref-type="bibr" rid="ref1">ing”. In: 2018</xref>
        IEEE Symposium on
Security and Privacy (SP). IEEE, May 2018, pp. 19–35. ISBN:
978-1-5386-4353-2. DOI: 10.1109/SP.2018.00057.
arXiv: 1804.00308.
      </p>
      <p>
        Ricky Laishram and Vir Virander Phoha. “Curie: A method
for protecting SVM Classifier from Poison
        <xref ref-type="bibr" rid="ref49">ing Attack”. In:
(June 2016</xref>
        ). arXiv: 1606.01584.
      </p>
      <p>Himabindu Lakkaraju, Ece Kamar, Rich Caruana, and Jure
Leskovec. “Interpretable &amp; Explorable Approximations of
Black Box Models”. In: (2017). arXiv: 1707.01154.
[31] Jamie Hayes and George Danezis. “Machine Learning as an
Adversarial Service: Learning Black-Box Adversarial
Examples”. In: (2017). arXiv: 1708.05207.
[38]
[39]
[40]
[41]
[42]
[43]
[44]
[45]
[46]
[47]
[48]</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <source>In: IEEE Access 6 (Jan</source>
          .
          <year>2018</year>
          ), pp.
          <fpage>14410</fpage>
          -
          <lpage>14430</lpage>
          . ISSN: 21693536. DOI:
          <volume>10</volume>
          .1109/ACCESS.
          <year>2018</year>
          .
          <volume>2807385</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          arXiv:
          <year>1801</year>
          .00553.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Ibrahim</surname>
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Alabdulmohsin</surname>
            ,
            <given-names>Xin</given-names>
          </string-name>
          <string-name>
            <surname>Gao</surname>
          </string-name>
          , and Xiangliang Zhang. “
          <article-title>Adding Robustness to Support Vector Machines Against Adversarial Reverse Engineering”</article-title>
          .
          <source>In: Proceedings of the 23rd ACM International Conference on Conference on Information and Knowledge</source>
          Management - CIKM '
          <fpage>14</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          New York, New York, USA: ACM Press,
          <year>2014</year>
          , pp.
          <fpage>231</fpage>
          -
          <lpage>240</lpage>
          . ISBN: 9781450325981. DOI:
          <volume>10</volume>
          .1145/2661829.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <article-title>“Crafting Adversarial Attacks on Recurrent Neural Networks”</article-title>
          . In: (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <string-name>
            <surname>In:</surname>
          </string-name>
          (
          <year>2013</year>
          ). ISSN:
          <fpage>1747</fpage>
          -
          <lpage>8405</lpage>
          . DOI:
          <volume>10</volume>
          . 1504 / IJSN .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <year>2015</year>
          .071829. arXiv:
          <volume>1306</volume>
          .
          <fpage>4447</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <string-name>
            <given-names>Shumeet</given-names>
            <surname>Baluja</surname>
          </string-name>
          and
          <string-name>
            <given-names>Ian</given-names>
            <surname>Fischer</surname>
          </string-name>
          . “
          <article-title>Adversarial Transformation Networks: Learning to Generate Adversarial Examples”</article-title>
          . In: (
          <year>2017</year>
          ). arXiv:
          <volume>1703</volume>
          .
          <fpage>09387</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          <string-name>
            <given-names>Shumeet</given-names>
            <surname>Baluja</surname>
          </string-name>
          and
          <string-name>
            <given-names>Ian</given-names>
            <surname>Fischer</surname>
          </string-name>
          . “
          <article-title>Learning to Attack: Adversarial Transformation Networks”</article-title>
          .
          <source>In: Association for the Advancement of Artificial Intelligence - AAAI'18</source>
          .
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          <string-name>
            <surname>Joseph</surname>
            ,
            <given-names>and J. D. Tygar. “</given-names>
          </string-name>
          <article-title>Can machine learning be secure?”</article-title>
          <source>In: Proceedings of the 2006 ACM Symposium on Information, computer and communications security - ASIACCS '06</source>
          . New York, USA: ACM Press,
          <year>2006</year>
          . ISBN: 1595932720. DOI:
          <volume>10</volume>
          .1145/1128817.1128824.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          <string-name>
            <given-names>Alex</given-names>
            <surname>Beatson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Zhaoran</given-names>
            <surname>Wang</surname>
          </string-name>
          , and Han Liu. “
          <article-title>Blind Attacks on Machine Learners”</article-title>
          .
          <source>In: 30th Conference on Neural Information Processing Systems (NIPS</source>
          <year>2016</year>
          )
          <article-title>(</article-title>
          <year>2016</year>
          ), pp.
          <fpage>2397</fpage>
          -
          <lpage>2405</lpage>
          . ISSN:
          <volume>10495258</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          Vol.
          <volume>3138</volume>
          . Lecture Notes in Computer Science. Berlin, Heidelberg: Springer Berlin Heidelberg, Aug.
          <year>2004</year>
          . ISBN:
          <fpage>978</fpage>
          -3-
          <fpage>540</fpage>
          -22570-
          <lpage>6</lpage>
          . DOI:
          <volume>10</volume>
          . 1007 / b98738. arXiv:
          <fpage>9780201398298</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          <string-name>
            <given-names>Battista</given-names>
            <surname>Biggio</surname>
          </string-name>
          , Igino Corona, Giorgio Fumera, Giorgio Giacinto, and Fabio Roli. “
          <article-title>Bagging classifiers for fighting poisoning attacks in adversarial classification tasks”</article-title>
          .
          <source>In: Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) 6713 LNCS</source>
          (
          <year>2011</year>
          ), pp.
          <fpage>350</fpage>
          -
          <lpage>359</lpage>
          . ISSN: 03029743. DOI:
          <volume>10</volume>
          . 1007 / 978 - 3 -
          <fpage>642</fpage>
          - 21557 - 5_
          <fpage>37</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          <string-name>
            <given-names>Battista</given-names>
            <surname>Biggio</surname>
          </string-name>
          , Igino Corona, Davide Maiorca, Blaine Nelson, Pavel Laskov, Giorgio Giacinto, and Fabio Roli. “
          <article-title>Evasion Attacks against Machine Learning at Test Time”</article-title>
          .
          <source>In: ECML PKDD</source>
          (
          <year>2013</year>
          ), pp.
          <fpage>387</fpage>
          -
          <lpage>402</lpage>
          . DOI:
          <volume>10</volume>
          .1007/978- 3-
          <fpage>642</fpage>
          -40994-3\_
          <fpage>25</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          <string-name>
            <given-names>Battista</given-names>
            <surname>Biggio</surname>
          </string-name>
          , Blaine Nelson, and Pavel Laskov. “
          <article-title>Poisoning Attacks against Support Vector Machines”</article-title>
          .
          <source>In: Proceedings of the 29 th International Conference on Machine Learning (June</source>
          <year>2012</year>
          ). arXiv:
          <volume>1206</volume>
          .
          <fpage>6389</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          <string-name>
            <given-names>Battista</given-names>
            <surname>Biggio</surname>
          </string-name>
          , Ignazio Pillai, Samuel Rota Bulo`,
          <string-name>
            <surname>Davide</surname>
            <given-names>Ariu</given-names>
          </string-name>
          , Marcello Pelillo, and Fabio Roli. “
          <article-title>Is data clustering in adversarial settings secure?”</article-title>
          <source>In: Proceedings of the 2013 ACM workshop on Artificial intelligence and security - AISec '13</source>
          (
          <year>2013</year>
          ), pp.
          <fpage>87</fpage>
          -
          <lpage>98</lpage>
          . ISSN: 15437221. DOI:
          <volume>10</volume>
          .1145/2517312.2517321.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          <string-name>
            <given-names>Battista</given-names>
            <surname>Biggio</surname>
          </string-name>
          , Konrad Rieck, Davide Ariu, Christian Wressnegger, Igino Corona, Giorgio Giacinto, and Fabio Roli. “
          <article-title>Poisoning behavioral malware clustering”</article-title>
          .
          <source>In: Proceedings of the 2014 Workshop on Artificial Intelligent and Security</source>
          Workshop - AISec '
          <fpage>14</fpage>
          . New York, USA: ACM Press,
          <year>Nov</year>
          .
          <year>2014</year>
          , pp.
          <fpage>27</fpage>
          -
          <lpage>36</lpage>
          . ISBN: 9781450331531. DOI:
          <volume>10</volume>
          .1145/2666652.2666666.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          <string-name>
            <given-names>Battista</given-names>
            <surname>Biggio</surname>
          </string-name>
          and
          <string-name>
            <given-names>Fabio</given-names>
            <surname>Roli</surname>
          </string-name>
          . “Wild Patterns:
          <article-title>Ten Years After the Rise of Adversarial Machine Learning”</article-title>
          .
          <source>In: Pattern Recognition</source>
          <volume>84</volume>
          (
          <issue>Dec</issue>
          .
          <year>2017</year>
          ), pp.
          <fpage>317</fpage>
          -
          <lpage>331</lpage>
          . ISSN: 00313203. DOI:
          <volume>10</volume>
          .1016/j.patcog.
          <year>2018</year>
          .
          <volume>07</volume>
          .023.
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          <source>arXiv: 1712</source>
          .
          <fpage>03141</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          <string-name>
            <given-names>Alexander</given-names>
            <surname>Binder</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Sebastian</given-names>
            <surname>Bach</surname>
          </string-name>
          , Gregoire Montavon, Klaus Robert Mu¨ller, and Wojciech Samek. “
          <article-title>Layer-wise relevance propagation for deep neural network architectures”</article-title>
          .
          <source>In: Lecture Notes in Electrical Engineering</source>
          <volume>376</volume>
          (
          <year>2016</year>
          ), pp.
          <fpage>913</fpage>
          -
          <lpage>922</lpage>
          . ISSN: 18761119. DOI:
          <volume>10</volume>
          . 1007 /
          <fpage>978</fpage>
          -981-10-0557-2_
          <fpage>87</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          <year>2017</year>
          ). arXiv:
          <volume>1712</volume>
          .
          <fpage>04248</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          <string-name>
            <given-names>Nicholas</given-names>
            <surname>Carlini</surname>
          </string-name>
          , Chang Liu, Jernej Kos, U´ lfar Erlingsson, and Dawn Song. “
          <article-title>The Secret Sharer: Measuring Unintended Neural Network Memorization &amp; Extracting Secrets”</article-title>
          .
          <source>In: (Feb</source>
          .
          <year>2018</year>
          ). arXiv:
          <year>1802</year>
          .08232.
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          <string-name>
            <given-names>Rich</given-names>
            <surname>Caruana</surname>
          </string-name>
          , Yin Lou, Johannes Gehrke, Paul Koch, Marc Sturm, and Noemie Elhadad. “
          <article-title>Intelligible Models for HealthCare”</article-title>
          .
          <source>In: Proceedings of the 21th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining - KDD '15</source>
          (
          <year>2015</year>
          ), pp.
          <fpage>1721</fpage>
          -
          <lpage>1730</lpage>
          . ISSN:
          <fpage>1869</fpage>
          -
          <lpage>0327</lpage>
          . DOI:
          <volume>10</volume>
          .1145/2783258.2788613.
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          <string-name>
            <given-names>Lingwei</given-names>
            <surname>Chen</surname>
          </string-name>
          , Yanfang Ye, and
          <string-name>
            <surname>Thirimachos Bourlai. “</surname>
          </string-name>
          <article-title>Adversarial machine learning in malware detection: Arms race between evasion attack and defense”</article-title>
          .
          <source>In: Proceedings - 2017 European Intelligence and Security Informatics Conference</source>
          , EISIC
          <year>2017</year>
          2017-
          <fpage>Janua</fpage>
          (
          <year>2017</year>
          ), pp.
          <fpage>99</fpage>
          -
          <lpage>106</lpage>
          . DOI:
          <volume>10</volume>
          .1109/EISIC.
          <year>2017</year>
          .
          <volume>21</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          <string-name>
            <given-names>Fabiano</given-names>
            <surname>Dalpiaz</surname>
          </string-name>
          , Elda Paja, and
          <string-name>
            <given-names>Paolo</given-names>
            <surname>Giorgini</surname>
          </string-name>
          . Security Requirements Engineering:
          <article-title>Designing Secure SocioTechnical Systems</article-title>
          . MIT Press,
          <year>2016</year>
          , p.
          <fpage>224</fpage>
          . ISBN:
          <volume>0262034212</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          <string-name>
            <given-names>Nilesh</given-names>
            <surname>Dalvi</surname>
          </string-name>
          , Pedro Domingos, Mausam,
          <string-name>
            <given-names>Sumit</given-names>
            <surname>Sanghai</surname>
          </string-name>
          , and Deepak Verma. “
          <article-title>Adversarial classification”</article-title>
          .
          <source>In: Proceedings of the 2004 ACM SIGKDD international conference on Knowledge discovery and data mining - KDD '04.</source>
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          New York, USA: ACM Press,
          <year>2004</year>
          . DOI:
          <volume>10</volume>
          . 1145 / 1014052.1014066.
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          <string-name>
            <given-names>Hung</given-names>
            <surname>Dang</surname>
          </string-name>
          , Yue Huang, and
          <string-name>
            <surname>Ee-Chien Chang</surname>
          </string-name>
          . “
          <article-title>Evading Classifiers by Morphing in the Dark”</article-title>
          .
          <source>In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security - CCS '17</source>
          . New York, USA: ACM Press,
          <year>2017</year>
          , pp.
          <fpage>119</fpage>
          -
          <lpage>133</lpage>
          . ISBN: 9781450349468. DOI:
          <volume>10</volume>
          .1145/3133956.3133978. arXiv:
          <volume>1705</volume>
          .
          <fpage>07535</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          <string-name>
            <given-names>Ambra</given-names>
            <surname>Demontis</surname>
          </string-name>
          , Paolo Russu, Battista Biggio, Giorgio Fumera, and Fabio Roli. “
          <article-title>On security and sparsity of linear classifiers for adversarial settings”</article-title>
          .
          <source>In: Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) 10029 LNCS</source>
          (
          <year>2016</year>
          ), pp.
          <fpage>322</fpage>
          -
          <lpage>332</lpage>
          . ISSN: 16113349. DOI: Pavel Laskov and
          <string-name>
            <given-names>Marius</given-names>
            <surname>Kloft</surname>
          </string-name>
          .
          <article-title>“A framework for quantitative security analysis of machine learning”</article-title>
          .
          <source>In: Proceedings of the 2nd ACM workshop on Security and artificial intelligence - AISec</source>
          '
          <fpage>09</fpage>
          . New York, New York, USA: ACM Press,
          <year>2009</year>
          . ISBN: 9781605587813. DOI:
          <volume>10</volume>
          .1145/1654988.
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          <string-name>
            <given-names>Bo</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Yining</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Aarti</given-names>
            <surname>Singh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>and Yevgeniy</given-names>
            <surname>Vorobeychik</surname>
          </string-name>
          .
          <article-title>“Data Poisoning Attacks on Factorization-Based Collaborative Filtering”</article-title>
          .
          <source>In: 29th Conference on Neural Information Processing Systems (NIPS</source>
          <year>2016</year>
          )
          <article-title>Nips (Aug</article-title>
          .
          <year>2016</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          <source>ISSN: 10495258</source>
          . arXiv:
          <volume>1608</volume>
          .
          <fpage>08182</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          <string-name>
            <surname>Yen Chen Lin</surname>
          </string-name>
          , Zhang Wei Hong, Yuan Hong Liao, Meng Li Shih, Ming Yu Liu, and Min Sun. “
          <article-title>Tactics of adversarial attack on deep reinforcement learning agents”</article-title>
          .
          <source>In: IJCAI International Joint Conference on Artificial Intelligence</source>
          (
          <year>2017</year>
          ), pp.
          <fpage>3756</fpage>
          -
          <lpage>3762</lpage>
          . ISSN:
          <volume>10450823</volume>
          . arXiv:
          <volume>1703</volume>
          .
          <fpage>06748</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          <article-title>“Robust Linear Regression Against Training Data Poisoning”</article-title>
          .
          <source>In: Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security - AISec '17</source>
          (
          <year>2017</year>
          ), pp.
          <fpage>91</fpage>
          -
          <lpage>102</lpage>
          . DOI:
          <volume>10</volume>
          .1145/3128572.3140447.
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          <string-name>
            <given-names>Qiang</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Pan</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Wentao</given-names>
            <surname>Zhao</surname>
          </string-name>
          ,
          <string-name>
            <surname>Wei</surname>
            <given-names>Cai</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shui Yu</surname>
          </string-name>
          , and
          <string-name>
            <surname>Victor C.M.</surname>
          </string-name>
          <article-title>Leung. “A survey on security threats and defensive techniques of machine learning: A data driven view”</article-title>
          .
          <source>In: IEEE Access 6</source>
          (
          <year>2018</year>
          ), pp.
          <fpage>12103</fpage>
          -
          <lpage>12117</lpage>
          . ISSN: 21693536. DOI:
          <volume>10</volume>
          .1109/ACCESS.
          <year>2018</year>
          .
          <volume>2805680</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          <string-name>
            <given-names>Yingqi</given-names>
            <surname>Liu</surname>
          </string-name>
          , Shiqing Ma, Yousra Aafer,
          <string-name>
            <surname>Wen-Chuan</surname>
            <given-names>Lee</given-names>
          </string-name>
          , Juan Zhai, Authors Yingqi Liu,
          <string-name>
            <given-names>Weihang</given-names>
            <surname>Wang</surname>
          </string-name>
          , and Xiangyu Zhang. “
          <article-title>Trojaning Attack on Neural Networks”</article-title>
          . In:
          <article-title>NDSS 2018 (Network and Distributed System Security Symposium) (Feb</article-title>
          .
          <year>2018</year>
          ). DOI:
          <volume>10</volume>
          . 14722 / ndss .
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          <string-name>
            <given-names>Daniel</given-names>
            <surname>Lowd</surname>
          </string-name>
          and
          <string-name>
            <given-names>Christopher</given-names>
            <surname>Meek</surname>
          </string-name>
          . “
          <article-title>Adversarial learning”</article-title>
          . In:
          <article-title>Proceeding of the eleventh ACM SIGKDD international conference on Knowledge discovery in data mining -</article-title>
          <source>KDD '05</source>
          (
          <year>2005</year>
          ).
          <source>DOI: 10.1145/1081870</source>
          .1081950.
        </mixed-citation>
      </ref>
      <ref id="ref37">
        <mixed-citation>
          <string-name>
            <given-names>Seyed</given-names>
            <surname>Mohsen</surname>
          </string-name>
          Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard. “
          <article-title>Universal adversarial perturbations”</article-title>
          .
          <source>In: Proceedings - 30th IEEE Conference on Computer Vision</source>
          and Pattern Recognition,
          <string-name>
            <surname>CVPR</surname>
          </string-name>
          <year>2017</year>
          2017-
          <fpage>January</fpage>
          (
          <year>2017</year>
          ), pp.
          <fpage>86</fpage>
          -
          <lpage>94</lpage>
          . ISSN:
          <fpage>1063</fpage>
          -
          <lpage>6919</lpage>
          . DOI: 10 .
        </mixed-citation>
      </ref>
      <ref id="ref38">
        <mixed-citation>
          1109/CVPR.
          <year>2017</year>
          .
          <volume>17</volume>
          . arXiv:
          <volume>1705</volume>
          .
          <fpage>09554</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref39">
        <mixed-citation>
          <source>In: IEEE Journal of Biomedical and Health Informatics 19.6</source>
          (
          <issue>2015</issue>
          ), pp.
          <fpage>1893</fpage>
          -
          <lpage>1905</lpage>
          . ISSN: 21682194. DOI: 10 .
        </mixed-citation>
      </ref>
      <ref id="ref40">
        <mixed-citation>
          1109/JBHI.
          <year>2014</year>
          .
          <volume>2344095</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref41">
        <mixed-citation>
          <string-name>
            <given-names>Luis</given-names>
            <surname>Mun</surname>
          </string-name>
          <article-title>˜oz-Gonza´lez, Battista Biggio</article-title>
          , Ambra Demontis, Andrea Paudice, Vasin Wongrassamee, Emil C. Lupu, and Fabio Roli. “
          <article-title>Towards Poisoning of Deep Learning Algorithms with Back-gradient Optimization”</article-title>
          .
          <source>In: Proceedings of the 10th ACM Workshop on Artificial Intelligence and</source>
          Security - AISec '
          <fpage>17</fpage>
          . New York,
          <string-name>
            <surname>SA</surname>
          </string-name>
          : ACM Press,
          <year>2017</year>
          , pp.
          <fpage>27</fpage>
          -
          <lpage>38</lpage>
          . ISBN: 9781450352024. DOI:
          <volume>10</volume>
          .1145/ 3128572.3140451. arXiv:
          <volume>1708</volume>
          .
          <fpage>08689</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref42">
        <mixed-citation>
          <string-name>
            <given-names>Blaine</given-names>
            <surname>Nelson</surname>
          </string-name>
          , Marco Barreno, Fuching Jack Chi,
          <string-name>
            <given-names>Anthony D.</given-names>
            <surname>Joseph</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Benjamin I.P.</given-names>
            <surname>Rubinstein</surname>
          </string-name>
          , Udam Saini,
          <string-name>
            <given-names>Charles</given-names>
            <surname>Sutton</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. D.</given-names>
            <surname>Tygar</surname>
          </string-name>
          , and
          <string-name>
            <surname>Kai Xia. “</surname>
          </string-name>
          <article-title>Exploiting machine learning to subvert your spam filter”</article-title>
          .
          <source>In: In Proceedings of the First Workshop on Large-scale Exploits and Emerging Threats (LEET) April</source>
          (
          <year>2008</year>
          ),
          <article-title>Article 7</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref43">
        <mixed-citation>
          <string-name>
            <surname>Tam N. Nguyen. “</surname>
          </string-name>
          <article-title>Attacking Machine Learning models as part of a cyber kill chain”</article-title>
          . In: (
          <year>2017</year>
          ). arXiv:
          <fpage>1705</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref44">
        <mixed-citation>
          <string-name>
            <given-names>Andrew P.</given-names>
            <surname>Norton</surname>
          </string-name>
          and
          <string-name>
            <given-names>Yanjun</given-names>
            <surname>Qi</surname>
          </string-name>
          . “
          <article-title>AdversarialPlayground: A visualization suite showing how adversarial examples fool deep learning”</article-title>
          .
          <source>In: 2017 IEEE Symposium on Visualization for Cyber Security (VizSec)</source>
          . Vol. 2017- Octob. IEEE, Oct.
          <year>2017</year>
          . ISBN:
          <fpage>978</fpage>
          -1-
          <fpage>5386</fpage>
          -2693-1.
        </mixed-citation>
      </ref>
      <ref id="ref45">
        <mixed-citation>
          <source>DOI: 10 . 1109 / VIZSEC</source>
          .
          <year>2017</year>
          .
          <volume>8062202</volume>
          . arXiv:
          <volume>1708</volume>
          .
          <fpage>00807</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref46">
        <mixed-citation>
          <string-name>
            <given-names>Nicolas</given-names>
            <surname>Papernot</surname>
          </string-name>
          .
          <article-title>“Characterizing the Limits and Defenses of Machine Learning in Adversarial Settings”</article-title>
          . In: (
          <year>2018</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref47">
        <mixed-citation>
          <article-title>“Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples”</article-title>
          . In: (
          <year>2016</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref48">
        <mixed-citation>
          <source>arXiv: 1605</source>
          .
          <fpage>07277</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref49">
        <mixed-citation>
          <source>In: (Feb</source>
          .
          <year>2016</year>
          ).
          <source>DOI: 10 . 1145 / 3052973</source>
          . 3053009.
        </mixed-citation>
      </ref>
      <ref id="ref50">
        <mixed-citation>
          <source>arXiv: 1602</source>
          .
          <fpage>02697</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref51">
        <mixed-citation>
          <string-name>
            <given-names>Nicolas</given-names>
            <surname>Papernot</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Patrick</given-names>
            <surname>Mcdaniel</surname>
          </string-name>
          ,
          <string-name>
            <surname>Somesh Jha</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Matt</given-names>
            <surname>Fredrikson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z. Berkay</given-names>
            <surname>Celik</surname>
          </string-name>
          , and Ananthram Swami. “
          <article-title>The limitations of deep learning in adversarial settings”</article-title>
          .
          <source>In: Proceedings - 2016 IEEE European Symposium on Security and Privacy, EURO S and P</source>
          <year>2016</year>
          (
          <year>2016</year>
          ), pp.
          <fpage>372</fpage>
          -
          <lpage>387</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref52">
        <mixed-citation>
          <source>DOI: 10</source>
          . 1109 / EuroSP .
          <year>2016</year>
          .
          <volume>36</volume>
          . arXiv:
          <fpage>1511</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref53">
        <mixed-citation>
          <string-name>
            <given-names>Nicolas</given-names>
            <surname>Papernot</surname>
          </string-name>
          ,
          <string-name>
            <surname>Patrick</surname>
            <given-names>McDaniel</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Arunesh</given-names>
            <surname>Sinha</surname>
          </string-name>
          , and
          <string-name>
            <given-names>Michael</given-names>
            <surname>Wellman</surname>
          </string-name>
          . “
          <article-title>SoK: Towards the Science of Security and Privacy in Machine Learning”</article-title>
          .
          <source>In: (Nov</source>
          .
          <year>2016</year>
          ). arXiv:
          <volume>1611</volume>
          .
          <fpage>03814</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref54">
        <mixed-citation>
          <string-name>
            <given-names>Nicolas</given-names>
            <surname>Papernot</surname>
          </string-name>
          ,
          <string-name>
            <surname>Patrick</surname>
            <given-names>McDaniel</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Arunesh</given-names>
            <surname>Sinha</surname>
          </string-name>
          , and
          <string-name>
            <given-names>Michael P.</given-names>
            <surname>Wellman</surname>
          </string-name>
          . “
          <article-title>SoK: Security and Privacy in Machine Learning”</article-title>
          .
          <source>In: 2018 IEEE European Symposium on Security</source>
          and
          <string-name>
            <surname>Privacy (EuroS&amp;P).</surname>
            <given-names>IEEE</given-names>
          </string-name>
          , Apr.
          <year>2018</year>
          , pp.
          <fpage>399</fpage>
          -
          <lpage>414</lpage>
          . ISBN:
          <fpage>978</fpage>
          -1-
          <fpage>5386</fpage>
          -4228-
          <lpage>3</lpage>
          . DOI:
          <volume>10</volume>
          .1109/ EuroSP.
          <year>2018</year>
          .
          <volume>00035</volume>
          . arXiv:
          <volume>1611</volume>
          .
          <fpage>03814</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref55">
        <mixed-citation>
          <string-name>
            <given-names>Nicolas</given-names>
            <surname>Papernot</surname>
          </string-name>
          ,
          <string-name>
            <surname>Patrick</surname>
            <given-names>McDaniel</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Ananthram</given-names>
            <surname>Swami</surname>
          </string-name>
          , and Richard Harang. “
          <article-title>Crafting adversarial input sequences for recurrent neural networks”</article-title>
          .
          <source>In: MILCOM</source>
          <year>2016</year>
          - 2016
          <string-name>
            <given-names>IEEE</given-names>
            <surname>Military</surname>
          </string-name>
          <article-title>Communications Conference</article-title>
          . IEEE, Nov.
        </mixed-citation>
      </ref>
      <ref id="ref56">
        <mixed-citation>
          <year>2016</year>
          , pp.
          <fpage>49</fpage>
          -
          <lpage>54</lpage>
          . ISBN:
          <fpage>978</fpage>
          -1-
          <fpage>5090</fpage>
          -3781-
          <lpage>0</lpage>
          . DOI: 10 .
        </mixed-citation>
      </ref>
      <ref id="ref57">
        <mixed-citation>
          1109 / MILCOM .
          <year>2016</year>
          .
          <volume>7795300</volume>
          . arXiv:
          <fpage>1604</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref58">
        <mixed-citation>
          <string-name>
            <surname>“”Why Should I Trust You</surname>
          </string-name>
          <article-title>?”: Explaining the Predictions of Any Classifier”</article-title>
          .
          <source>In: KDD '16 Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (Aug</source>
          .
          <year>2016</year>
          ), pp.
          <fpage>1135</fpage>
          -
          <lpage>1144</lpage>
          . ISSN: 9781450321389. DOI:
          <volume>10</volume>
          .1145/2939672.2939778.
        </mixed-citation>
      </ref>
      <ref id="ref59">
        <mixed-citation>
          <source>arXiv: 1602</source>
          .
          <fpage>04938</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref60">
        <mixed-citation>
          <string-name>
            <surname>Amir</surname>
            <given-names>Rosenfeld</given-names>
          </string-name>
          , Richard Zemel,
          <string-name>
            <surname>and John K. Tsotsos.</surname>
          </string-name>
          “
          <article-title>The Elephant in the Room”</article-title>
          . In: (
          <year>2018</year>
          ). arXiv:
          <year>1808</year>
          .03305.
        </mixed-citation>
      </ref>
      <ref id="ref61">
        <mixed-citation>
          <string-name>
            <surname>Benjamin</surname>
            <given-names>I.P.</given-names>
          </string-name>
          <string-name>
            <surname>Rubinstein</surname>
          </string-name>
          , Blaine Nelson, Ling Huang,
          <string-name>
            <surname>Anthony D Joseph</surname>
          </string-name>
          ,
          <article-title>Shing-hon Lau, Satish Rao, Nina Taft, and</article-title>
          <string-name>
            <given-names>J. D.</given-names>
            <surname>Tygar</surname>
          </string-name>
          . “ANTIDOTE:
          <article-title>Understanding and Defending against Poisoning of Anomaly Detectors”</article-title>
          .
          <source>In: Proceedings of the 9th ACM SIGCOMM conference on Internet measurement conference - IMC '09</source>
          . New York, New York, USA: ACM Press,
          <year>Nov</year>
          .
          <year>2009</year>
          . ISBN: 9781605587714. DOI:
          <volume>10</volume>
          .1145/1644893.1644895.
        </mixed-citation>
      </ref>
      <ref id="ref62">
        <mixed-citation>
          <string-name>
            <given-names>Paolo</given-names>
            <surname>Russu</surname>
          </string-name>
          , Ambra Demontis, Battista Biggio, Giorgio Fumera, and Fabio Roli. “
          <article-title>Secure Kernel Machines against Evasion Attacks”</article-title>
          .
          <source>In: Proceedings of the 2016 ACM Workshop on Artificial Intelligence and Security - ALSec '16</source>
          (
          <year>2016</year>
          ), pp.
          <fpage>59</fpage>
          -
          <lpage>69</lpage>
          . DOI:
          <volume>10</volume>
          .1145/2996758.2996771.
        </mixed-citation>
      </ref>
      <ref id="ref63">
        <mixed-citation>
          <article-title>“Poison Frogs! Targeted Clean-Label Poisoning Attacks on Neural Networks”</article-title>
          .
          <source>In: (Apr</source>
          .
          <year>2018</year>
          ). arXiv:
          <year>1804</year>
          .00792.
        </mixed-citation>
      </ref>
      <ref id="ref64">
        <mixed-citation>
          <string-name>
            <given-names>Reza</given-names>
            <surname>Shokri</surname>
          </string-name>
          , Marco Stronati, Congzheng Song, and Vitaly Shmatikov. “
          <article-title>Membership Inference Attacks Against Machine Learning Models”</article-title>
          .
          <source>In: Proceedings - IEEE Symposium on Security and Privacy</source>
          (
          <year>2017</year>
          ), pp.
          <fpage>3</fpage>
          -
          <lpage>18</lpage>
          . ISSN: 10816011. DOI:
          <volume>10</volume>
          .1109/SP.
          <year>2017</year>
          .
          <volume>41</volume>
          . arXiv:
          <fpage>1610</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref65">
        <mixed-citation>
          <string-name>
            <surname>D.B. Skillicorn</surname>
          </string-name>
          . “
          <article-title>Adversarial Knowledge Discovery”</article-title>
          .
          <source>In: IEEE Intelligent Systems 24.6</source>
          (
          <issue>2009</issue>
          ), pp.
          <fpage>1</fpage>
          -
          <lpage>13</lpage>
          . ISSN:
          <fpage>1541</fpage>
          -
          <lpage>1672</lpage>
          . DOI:
          <volume>10</volume>
          .1109/MIS.
          <year>2009</year>
          .
          <volume>108</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref66">
        <mixed-citation>
          <string-name>
            <given-names>Congzheng</given-names>
            <surname>Song</surname>
          </string-name>
          , Thomas Ristenpart, and Vitaly Shmatikov. “
          <article-title>Machine Learning Models that Remember Too Much”</article-title>
          . In: (
          <year>2017</year>
          ).
          <source>ISSN: 15437221. DOI: 10.1145/3133956</source>
          .3134077. arXiv:
          <volume>1709</volume>
          .
          <fpage>07886</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref67">
        <mixed-citation>
          <string-name>
            <surname>Nedim Sˇrndic</surname>
            ´ and
            <given-names>Pavel</given-names>
          </string-name>
          <string-name>
            <surname>Laskov</surname>
          </string-name>
          . “
          <article-title>Practical evasion of a learning-based classifier: A case study”</article-title>
          .
          <source>In: Proceedings - IEEE Symposium on Security and Privacy</source>
          (
          <year>2014</year>
          ), pp.
          <fpage>197</fpage>
          -
          <lpage>211</lpage>
          . ISSN: 10816011. DOI:
          <volume>10</volume>
          .1109/SP.
          <year>2014</year>
          .
          <volume>20</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref68">
        <mixed-citation>
          <string-name>
            <given-names>Xi</given-names>
            <surname>Wu</surname>
          </string-name>
          , Matthew Fredrikson, Somesh Jha,
          <string-name>
            <given-names>and Jeffrey F.</given-names>
            <surname>Naughton</surname>
          </string-name>
          . “
          <article-title>A methodology for formalizing modelinversion attacks”</article-title>
          .
          <source>In: Proceedings - IEEE Computer Security Foundations Symposium 2016-Augus</source>
          (
          <year>2016</year>
          ).
          <source>ISSN: 19401434</source>
          . DOI:
          <volume>10</volume>
          .1109/CSF.
          <year>2016</year>
          .
          <volume>32</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref69">
        <mixed-citation>
          <string-name>
            <given-names>Han</given-names>
            <surname>Xiao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Huang</given-names>
            <surname>Xiao</surname>
          </string-name>
          , and Claudia Eckert. “
          <article-title>Adversarial label flips attack on support vector machines”</article-title>
          .
          <source>In: Frontiers in Artificial Intelligence and Applications</source>
          <volume>242</volume>
          .4 (
          <issue>2012</issue>
          ), pp.
          <fpage>870</fpage>
          -
          <lpage>875</lpage>
          . ISSN: 09226389. DOI:
          <volume>10</volume>
          .3233/978- 1-
          <fpage>61499</fpage>
          -098-7-870.
        </mixed-citation>
      </ref>
      <ref id="ref70">
        <mixed-citation>
          <string-name>
            <given-names>Huang</given-names>
            <surname>Xiao</surname>
          </string-name>
          , Battista Biggio, Blaine Nelson, Han Xiao,
          <string-name>
            <given-names>Claudia</given-names>
            <surname>Eckert</surname>
          </string-name>
          , and Fabio Roli. “
          <article-title>Support vector machines under adversarial label contamination”</article-title>
          .
          <source>In: Neurocomputing</source>
          <volume>160</volume>
          (
          <year>2015</year>
          ), pp.
          <fpage>53</fpage>
          -
          <lpage>62</lpage>
          . ISSN: 18728286. DOI: 10 .
        </mixed-citation>
      </ref>
      <ref id="ref71">
        <mixed-citation>
          1016/j.neucom.
          <year>2014</year>
          .
          <volume>08</volume>
          .081.
        </mixed-citation>
      </ref>
      <ref id="ref72">
        <mixed-citation>
          <article-title>“Sparse Feature Attacks in Adversarial Learning”</article-title>
          .
          <source>In: IEEE Transactions on Knowledge and Data Engineering</source>
          <volume>30</volume>
          .6 (
          <issue>2018</issue>
          ), pp.
          <fpage>1164</fpage>
          -
          <lpage>1177</lpage>
          . ISSN: 10414347. DOI:
          <volume>10</volume>
          .1109/ TKDE.
          <year>2018</year>
          .
          <volume>2790928</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref73">
        <mixed-citation>
          [67]
          <string-name>
            <surname>Jacob</surname>
            <given-names>Steinhardt</given-names>
          </string-name>
          , Pang Wei Koh, and Percy Liang. “
          <article-title>Certified Defenses for Data Poisoning Attacks”</article-title>
          .
          <source>In: (June</source>
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref74">
        <mixed-citation>
          <source>ISSN: 10495258</source>
          . arXiv:
          <volume>1706</volume>
          .
          <fpage>03691</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref75">
        <mixed-citation>
          <string-name>
            <given-names>Rock</given-names>
            <surname>Stevens</surname>
          </string-name>
          , Octavian Suciu, Andrew Ruef, Sanghyun Hong,
          <string-name>
            <given-names>Michael</given-names>
            <surname>Hicks</surname>
          </string-name>
          , and Tudor Dumitras¸. “Summoning Demons:
          <article-title>The Pursuit of Exploitable Bugs in Machine Learning”</article-title>
          .
          <source>In: (Jan</source>
          .
          <year>2017</year>
          ). arXiv:
          <volume>1701</volume>
          .
          <fpage>04739</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref76">
        <mixed-citation>
          <article-title>“Intriguing properties of neural networks”</article-title>
          .
          <source>In: (Dec</source>
          .
          <year>2013</year>
          ), pp.
          <fpage>1</fpage>
          -
          <lpage>10</lpage>
          . ISSN: 15499618. DOI:
          <volume>10</volume>
          .1021/ct2009208.
        </mixed-citation>
      </ref>
      <ref id="ref77">
        <mixed-citation>
          <source>arXiv: 1312</source>
          .
          <fpage>6199</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref78">
        <mixed-citation>
          <string-name>
            <given-names>Pedro</given-names>
            <surname>Tabacof</surname>
          </string-name>
          and
          <string-name>
            <given-names>Eduardo</given-names>
            <surname>Valle</surname>
          </string-name>
          .
          <article-title>“Exploring the space of adversarial images”</article-title>
          .
          <source>In: Proceedings of the International Joint Conference on Neural Networks 2016-Octob.1</source>
          (
          <issue>2016</issue>
          ), pp.
          <fpage>426</fpage>
          -
          <lpage>433</lpage>
          . DOI:
          <volume>10</volume>
          . 1109 / IJCNN .
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref79">
        <mixed-citation>
          7727230. arXiv:
          <volume>1510</volume>
          .
          <fpage>05328</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref80">
        <mixed-citation>
          <string-name>
            <surname>Florian</surname>
            <given-names>Trame`</given-names>
          </string-name>
          r, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and
          <article-title>Patrick McDaniel. “The Space of Transferable Adversarial Examples”</article-title>
          . In: (
          <year>2017</year>
          ). arXiv:
          <volume>1704</volume>
          .
          <fpage>03453</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref81">
        <mixed-citation>
          <string-name>
            <surname>Florian</surname>
            <given-names>Trame`</given-names>
          </string-name>
          r, Fan Zhang, Ari Juels,
          <string-name>
            <given-names>Michael K.</given-names>
            <surname>Reiter</surname>
          </string-name>
          , and Thomas Ristenpart.
          <article-title>“Stealing Machine Learning Models via Prediction APIs”</article-title>
          .
          <source>In: Proceedings of the 25th USENIX Security Symposium</source>
          <volume>94</volume>
          .3 (
          <issue>Sept</issue>
          .
          <year>2016</year>
          ), pp.
          <fpage>601</fpage>
          -
          <lpage>618</lpage>
          . ISSN:
          <fpage>2469</fpage>
          -
          <lpage>9985</lpage>
          . DOI:
          <volume>10</volume>
          .1103/PhysRevC.94.
        </mixed-citation>
      </ref>
      <ref id="ref82">
        <mixed-citation>
          034301. arXiv:
          <volume>1609</volume>
          .
          <fpage>02943</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref83">
        <mixed-citation>
          <string-name>
            <given-names>Binghui</given-names>
            <surname>Wang</surname>
          </string-name>
          and Neil Zhenqiang Gong. “
          <article-title>Stealing Hyperparameters in Machine Learning”</article-title>
          .
          <source>In: Proceedings - IEEE Symposium on Security and Privacy</source>
          <year>2018</year>
          -May.May (
          <year>2018</year>
          ), pp.
          <fpage>36</fpage>
          -
          <lpage>52</lpage>
          . ISSN: 10816011. DOI:
          <volume>10</volume>
          .1109/SP.
        </mixed-citation>
      </ref>
      <ref id="ref84">
        <mixed-citation>
          <year>2018</year>
          .00038. arXiv:
          <year>1802</year>
          .05351.
        </mixed-citation>
      </ref>
      <ref id="ref85">
        <mixed-citation>
          <string-name>
            <given-names>“I</given-names>
            <surname>Know</surname>
          </string-name>
          <article-title>What You See: Power Side-Channel Attack on Convolutional Neural Network Accelerators”</article-title>
          . In: (
          <year>2018</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref86">
        <mixed-citation>
          arXiv:
          <year>1803</year>
          .05847.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>