Adversarial Feature Selection Against Evasion Attacks

Fei Zhang,Patrick P. K. Chan,Battista Biggio,Daniel S. Yeung,Fabio Roli
DOI: https://doi.org/10.1109/tcyb.2015.2415032
IF: 11.8
2016-01-01
IEEE Transactions on Cybernetics
Abstract:Pattern recognition and machine learning techniques have been increasinglyadopted in adversarial settings such as spam, intrusion and malware detection,although their security against well-crafted attacks that aim to evadedetection by manipulating data at test time has not yet been thoroughlyassessed. While previous work has been mainly focused on devisingadversary-aware classification algorithms to counter evasion attempts, only fewauthors have considered the impact of using reduced feature sets on classifiersecurity against the same attacks. An interesting, preliminary result is thatclassifier security to evasion may be even worsened by the application offeature selection. In this paper, we provide a more detailed investigation ofthis aspect, shedding some light on the security properties of featureselection against evasion attacks. Inspired by previous work on adversary-awareclassifiers, we propose a novel adversary-aware feature selection model thatcan improve classifier security against evasion attacks, by incorporatingspecific assumptions on the adversary's data manipulation strategy. We focus onan efficient, wrapper-based implementation of our approach, and experimentallyvalidate its soundness on different application examples, including spam andmalware detection.
What problem does this paper attempt to address?