Protecting the Protector, Hardening Machine Learning Defenses Against Adversarial Attacks @HackersOnBoard
Protecting the Protector, Hardening Machine Learning Defenses Against Adversarial Attacks  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 2 days ago
Humans are susceptible to social engineering. Machines are susceptible to tampering. Machine learning is vulnerable to adversarial attacks. Researchers have been able to successfully attack deep learning models used to classify malware to completely change their predictions by only accessing the output label of the model for the input samples fed by the attacker. Moreover, we've also seen attackers attempting to poison our training data for ML models by sending fake telemetry and trying to fool the classifier into believing that a given set of malware samples are actually benign. How do we detect and protect against such attacks? Is there a way we can make our models more robust to future attacks?

We'll discuss several strategies to make machine learning models more tamper resilient. We'll compare the difficulty of tampering with cloud-based models and client-based models. We'll discuss research that shows how singular models are susceptible to tampering, and some techniques, like stacked ensemble models, can be used to make them more resilient. We also talk about the importance of diversity in base ML models and technical details on how they can be optimized to handle different threat scenarios. Lastly, we'll describe suspected tampering activity we've witnessed using protection telemetry from over half a billion computers, and whether our mitigations worked.

Black Hat USA 2018
Protecting the Protector, Hardening Machine Learning Defenses Against Adversarial AttacksDEF CON 27 - Infiltrating Corporate Intranet Like NSA _Pre-auth RCE on Leading SSL VPNsDEF CON 27 - Dirk-jan Mollema - Im In Your Cloud Pwning Your Azure EnvironmentBlack Hat USA 2018 - Real Eyes, Realize, Real Lies Beating Deception TechnologiesDEF CON 27 - Roger Dingledine - The Tor Censorship Arms Race The Next ChapterDEF CON 27 - Truman Kain - Surveillance Detection Scout Your Lookout on AutopilotDEF CON 27 - Jmaxxz - Your Car is My CarHow TRITON Disrupted Safety Systems & Changed the Threat Landscape of IndustrialHow can Communities Move Forward After Incidents of Sexual Harassment or AssaultDEF CON 27 - Jacob Baines - Help Me Vulnerabilities Youre My Only HopeDEF CON 27 - Eyal Itkin - Say Cheese How I Ransomwared Your DSLR CameraDEF CON 27 - Bill Demirkapi - Are Your Childs Records at Risk The Current State of School Infosec
HackersOnBoard |

Protecting the Protector, Hardening Machine Learning Defenses Against Adversarial Attacks

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER