Security threats and solution strategies in the application of large-scale artificial intelligence model
Online published: 2024-05-18
Copyright
As computer hardware and algorithm technology improve by leaps and bounds in recent years, the artificial intelligence technology represented by large-scale model has shown greater advantages than human beings in many fields. However, AI-based systems are often vulnerable to a variety of security threats during initial data collection and preparation, training and reasoning, and deployment. In AI-based systems, the data acquisition and preprocessing stage is vulnerable to sensor spoofing attacks, and the model training and inference stage is vulnerable to poisoning attacks and adversarial attacks. In order to address these security threats against AI systems, the challenges and solution strategies faced by AI large-scale model security were summarized, so that AI technology based on large-scale model could be utilized in industrial applications. Specifically, the AI large-scale model and its characteristics are introduced, and then the technical risks and security vulnerabilities of the AI large-scale model were summarized and analyzed. Finally, the research areas and challenges of AI large-scale model security detection and protection were discussed.
LIU Yishi , ZHOU Yajian , CUI Ying , LIU Jianwei . Security threats and solution strategies in the application of large-scale artificial intelligence model[J]. Journal of Cybersecurity, 2024 , 2(1) : 83 -91 . DOI: 10.20172/j.issn.2097-3136.240107
| 1 |
HU Y, KUANG W, QIN Z, et al. Artificial intelligence security: Threats and countermeasures[J]. ACM Computing Surveys, 2021, 55 (1): 1- 36.
|
| 2 |
新华社,赛迪智库. 冷观人工智能大模型热[J]. 软件和集成电路,2023(7):60-63.
XIN H S,SAIDI Z K. Cool observation of the heat in large AI models[J]. Software and Integrated Circuit,2023(7):60-63.
|
| 3 |
任奎, 孟泉润, 闫守琨, 等. 人工智能模型数据泄露的攻击与防御研究综述[J]. 网络与信息安全学报, 2021, 7 (1): 1- 10.
REN K, MENG Q R, YAN S K, et al. Survey of artificial intelligence data security and privacy protection[J]. Chinese Journal of Network and Information Security, 2021, 7 (1): 1- 10.
|
| 4 |
周文斌, 刘雨琦. 现在讨论AI安全, 为时尚早吗[J]. 大数据时代, 2023, (7): 58- 80.
ZHOU W B, LIU Y Q, et al. Is it too early to talk about AI security[J]. Big Data Time, 2023, (7): 58- 80.
|
| 5 |
CHAKRABORTY A, ALAM M, DEY V, et al. Adversarial attacks and defences: A survey[J]. arXiv preprint arXiv:, 1810, 00069, 2018.
|
| 6 |
MENON S,DAMIAN A,HU S,et al. PULSE:self-supervised photo up sampling via latent space exploration of generative models[C]//IEEE/CVF Conference on Computer Vision and Pattern Recognition. Virtual:IEEE,2020:2437–2445.
|
| 7 |
OZDAG M. Adversarial attacks and defenses against deep neural networks: A survey[J]. Procedia Computer Science, 2018, 140, 152- 161.
|
| 8 |
YAKURA H, SAKUMA J. Robust audio adversarial example for a physical attack[J]. arXiv preprint arXiv:, 1810, 11793, 2018.
|
| 9 |
ZHANG J, LI C. Adversarial examples: opportunities and challenges[J]. IEEE Transactions on Neural Networks and Learning Systems, 2020, 31 (7): 2578- 2593.
|
| 10 |
LIN H. Large-scale artificial intelligence models[J]. Computer, 2022, 55 (5): 76- 80.
|
| 11 |
LI Z,WANG C,MA P,et al. On the feasibility of specialized ability extracting for large language code models[EB]. arXiv preprint arXiv:2303. 03012,2023.
|
| 12 |
WANG Y, PAN Y, YAN M, et al. A survey on ChatGPT: AI-generated contents, challenges, and solutions[J]. IEEE Open Jounal of the Computer Society, 2023, 4, 280- 302.
|
| 13 |
WANG J,HU X,HOU W,et al. On the robustness of ChatGPT:An adversarial and out-of-distribution perspective[EB]. arXiv preprint arXiv:2302. 12095,2023.
|
| 14 |
Alawida M, Meiri S, Mehmood A, et al. Acomprehensive study of ChatGPT: Advancements limitations and ethical considerations in natural language processing and cybersecurity[J]. Information, 2023, 14 (8): 462- 485.
|
| 15 |
中国支付清算协会.关于支付行业从业人员谨慎使用ChatGPT等工具的倡议[EB/OL]. (2023-04-10)[2024-01-10].https://www.pcac.org.cn/eportal/ui?pageId=598261&articleKey=617041&columnId=595085.
Payment & Clearing Association of China. Payment industry professionals advised to exercise caution when using tools like ChatGPT[[EB/OL]. (2023-04-10)[2024-01-10].https://www.pcac.org.cn/eportal/ui?pageId=598261&articleKey=617041&columnId=595085.
|
| 16 |
魏中原. AI概念板块无死角杀跌,主体炒作熄火后资金会流向哪些板块[EB]. 第一财经,2023-04-10.
WEI Z Y. The AI concept sector experiences a comprehensive sell-off,and after the main speculation cools down,which sectors will the capital flow into[EB]. China Business Network,2023-04-10.
|
| 17 |
陈戈. 类ChatGPT亟需加强监管[J]. 中国信息界, 2023, (2): 36- 37.
CHEN G. Tools like ChatGPT urgently require strengthened regulation[J]. Information China, 2023, (2): 36- 37.
|
| 18 |
于晗. 全面评估使用ChatGPT的风险[EB]. 中国银行保险报,2023-04-14.
YU H. Thoroughly assess the risks of using ChatGPT[EB]. China's Insurance Quote,2023-04-14.
|
| 19 |
秦蕊, 梁小龙, 李娟娟, 等. 平行科研院所: 从数字化转型到智能化变革[J]. 智能科学与技术学报, 2023, 5 (2): 212- 221.
QIN R, LIANG X L, LI J J, et al. Parallel scientific research institutes: from digital transformation to intelligent revolution[J]. Chinese Journal of Intelligent Science and Technology, 2023, 5 (2): 212- 221.
|
| 20 |
孔忠愿. 强人工智能刑事责任主体的理论厘清与理性反思[M]. 北京:法律出版社,2020:236-258.
KONG Z Y. Theoretical Clarification and Rational Reflection on the Subject of Criminal Responsibility for Strong Artificial Intelligence[M]. Law Press·China,2020:236-258.
|
| 21 |
信安标委大数据安全标准特别工作组. 人工智能安全标准化白皮书(2023版)[R]. 2023.
Cybersecurity Standards Committee Special Working Group on Big Data Security. White Paper on Artificial Intelligence Security Standardization (2023 Edition)[R].2023.
|
| 22 |
满孝颐. 数据安全:人工智能健康发展的核心命题[J]. 中国信息安全,2019(11):47-48.
MANG X Y. Data security:The central proposition for the healthy development of artificial intelligence[J]. China Information Security,2019(11):47-48.
|
| 23 |
HINNEFELD H, COOMAN P, MAMMO N, et al. Evaluating fairness metrics in the presence of dataset bias[J]. arXiv preprint arXiv:, 1809, 09245, 2018.
|
| 24 |
BIRNBAUM B,DERENZI B,FLAXMAN A,et al. Automated quality control for mobile data collection[C]// The 2nd ACM Symposium on Computing for Development. New York:ACM,2012.
|
| 25 |
REZVANI M,IGNJATOVIC A,BERTINO E,et al. Secure data aggregation technique for wireless sensor networks[J],IEEE Transactions on Dependable and Secure Computing,2014,12(1):98-110.
|
| 26 |
LI W, SONG H. ART: an attack-resistant trust management scheme for securing vehicular ad Hoc networks[J]. IEEE Transactions on Intelligent Transportation Systems, 2015, 17 (4): 960- 969.
|
| 27 |
SHOUKRY Y,MARTIN P,YONA Y,et al. PyCRA:Physical challenge response authentication for active sensors under spoofing attacks categories and subject descriptors[C]//The 22nd ACM SIGSAC Conference on Computer and Communications Security,2015:1004-1015.
|
| 28 |
KOH W,LIANG P. Understanding black-box predictions via influence functions[EB]. arXiv preprint arXiv:1703. 04730,2020.
|
| 29 |
HINTON G,VINYALS O,DEAN J. Distilling the knowledge in a neural network[EB]. arXiv preprint arXiv:1503. 02531,2015.
|
| 30 |
PAPERNOT N,MCDANIEL P,WU X,et al. Distillation as a defense to adversarial perturbations against deep neural networks[J]. IEEE Symposium on Security and Privacy,2016:582-597.
|
| 31 |
KATZ G,BARRETT C,DAVID L,et al. Reluplex:an efficient SMT solver for verifying deep neural networks[C]//The International Conference on Computer Aided Verification,2017:97-117.
|
| 32 |
TRAMER F,KURAKIN A,PAPERNOT N,et al. Ensemble adversarial training:attacks and defenses[C]//The 6th International Conference on Learning Representations,ICLR,2018.
|
| 33 |
MOHSEN S,DEZFOOLI M,FAWZI A,et al. Universal adversarial perturbations[C]//The IEEE Conference on Computer Vision and Pattern Recognition,2016:1765-1773.
|
| 34 |
MENG D,CHEN H. Magnet:A two-pronged defense against adversarial examples[C]//The 2017 ACM SIGSAC Conference on Computer and Communications Security,2017:135-147.
|
| 35 |
RAGHUNATHAN A,STEINHARDT J,LIANG P. Certified defenses against adversarial examples[EB]. arXiv preprint arXiv:1801. 09344,2018.
|
| 36 |
PRAKASH A,MORAN N,GARBER S,et al. Deflecting adversarial attacks with pixel deflection[C]//The IEEE Conference on Computer Vision and Pattern Recognition,2018:8571-8580.
|
| 37 |
祁利斌,李凯斌,时启顺. 人工智能时代数据安全面临的机遇与挑战[J]. 数字经济,2022(4):94-98.
QI L B,LI K B,SHI Q S. Opportunities and Challenges of Data Security in the Era of Artificial Intelligence[J]. Digital Economy,2022(4):94-98.
|
| 38 |
ZHANG J,PENG S,HU Y,et al. HRAE:Hardware-assisted randomization against adversarial example attacks[C]//The 2020 IEEE 29th Asian Test Symposium,2020:1-6.
|
| 39 |
ZHANG J,LI C. Adversarial examples:Opportunities and challenges[C]. IEEE Transactions on Neural Networks and Learning Systems,2020,31(7):2578-2593.
|
| 40 |
SZEGEDY C,ZAREMBA W,SUTSKEVER I,et al,Intriguing properties of neural networks[C]//The 2nd International Conference on Learning Representations,2013:1-10.
|
| 41 |
SU J, VARGAS D, SAKURAI K. One pixel attack for fooling deep neural networks[J]. IEEE Transactions on Evolutionary Computation, 2019, 23 (5): 828- 841.
|
| 42 |
REZVANI M,IGNJATOVIC A,BERTINO E. Secure data aggregation technique for wireless sensor networks in the presence of collusion attacks[J]. IEEE Transactions on Dependable and Secure Computing,2014,12(1):98-110.
|
| 43 |
RAO K,SAK H,PRABHAVALKAR R. Exploring architectures,data and units for streaming end to-end speech recognition with RNN-transducer[C]//The 2017 IEEE Automatic Speech Recognition and Understanding Workshop,2017:193-199.
|
| 44 |
OLTEANU A, CASTILLO C, DIAZ F. Social data: Biases, methodological pitfalls, and ethical boundaries[J]. Frontiers in Big Data, 2019, 13 (2): 13.
|
| 45 |
MOPURI K, GANESHAN A, BABU R. Generalizable data-free objective for crafting universal adversarial perturbations[J]. IEEE Transactions on Pattern Analysis and Machine Intelligence, 2018, 41 (10): 2452- 2465.
|
| 46 |
雷霞,罗雄麟. 深度学习可解释性研究综述[J]. 计算机应用,2022, 42(11):3588-3602.
LEI X,LUO X L. Review on interpretability of deep learning[J]. Journal of Computer Applications,2022, 42(11):3588-3602.
|
/
| 〈 |
|
〉 |