Security & Privacy
Adversarial machine learning
The study of ways to trick AI systems and ways to protect them.
Example
Researchers alter test pictures to see whether AI labels them incorrectly.
Why people use it
It studies how deliberate interference can make AI fail and how to resist it.
What you'll hear
“Could someone deliberately trick this system?”
What this means for you
Ask what the attacker could access and change when judging a security claim.
Can you control it?
Developer-only
The people building or running the AI choose this setup. An everyday user generally needs their help to change how this part works.
Common questions
- Is adversarial machine learning the same as ordinary AI system checking?
- No. It specifically considers deliberate manipulation by an adversary.
- Is an attack the same as an ordinary mistake?
- No. An attack involves deliberate interference, while an ordinary mistake may occur without anyone trying to cause it.
- Does a successful laboratory attack prove every real system is vulnerable?
- No. Access, equipment and other conditions may differ from actual use.