Authors: Pragati Bhandari, Aditya Patil, Prince Khalane, Mayuri Pawar, Kiran Salunke
Abstract: Artificial Intelligence (AI) and Machine Learning (ML) have completely changed the landscape of cybersecurity and added advanced capabilities for building these intelligent intrusion detection systems, malware classifiers, or anomaly detection frameworks. However, this integration has brought a new and particularly severe category of threats – adversarial attacks, which exploit the inherent vulnerabilities present in various AI and ML models to get round security mechanisms. This review paper represents systematic and comprehensive analysis of adversarial attacks against AI based cybersecurity systems. We conducted a survey of the taxonomy of adversarial attacks such as evasion, poisoning, model extraction, model inversion, and backdoor attacks and take a look at their methodologies, threat models and their real-life implications. We analysed attack algorithms starting from the Fast Gradient Sign Method (FGSM), Projected Gradient Descent, Carlini and Wagner (C&W) attacks, DeepFool, and new black-box methods including MI-FGSM and AutoAttack. Furthermore, we systematically evaluated state-of-the-art defence mechanisms also known as certified and adversarial training, input preprocessing, randomized smoothing and ensemble defences. We presented an empirical comparison of attack success rates from 6 AI-based intrusion detection systems and measure the success of defences under a variety of attack paradigms. Our analysis showed that while adversarial robustness has made great progress, there still exists a large attack capability-defensive mechanism discrepancy. This paper concludes with identification of open research challenges for the future and future directions that are crucial for creating trustworthy AI-based security systems.
International Journal of Science, Engineering and Technology