The Cyber Security Review | Monday, January 23, 2023
Cyber security measures are improving security measures by accounting for emerging AI-based threats like data poisoning and model poisoning, data extraction, model extraction, and model evasion.
FREMONT, CA: Software security is moving from focusing solely on traditional security layers to covering digital technology like API controls and pipeline security. Artificial intelligence (AI) based cyber security threats are emerging risks that penetration testing must center security review and penetration testing. Cyber attackers are evolving their approach to security breaches, adapting to new security measures and moving to other measures not secured against emerging threats.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Companies need to be aware of AI-based security threats to improve security holistically. Penetration testers can account for the following tests while testing:
Data poisoning: Machine learning models utilize training data that attackers can influence to manipulate action. Attackers contaminate algorithms and create a backdoor to create faulty ML models that attackers can control. Data poisoning can lead to further attacks like model evasion.
Model poisoning: Attackers choose to target the model instead of the data. Companies use pre-trained machine learning models, and attackers compromise these models with backdoors to gain access to their decision-making process. Model poisoning affects multiple users.
Data extraction: Cyber attackers gain access to the data to source type of ML training data by querying the model. They can gain access to sensitive data from the attacker as they can infer the data used in the model's training. Data extraction, or membership inference, does not need attackers to access the model's functionality, but they can observe the model's output.
Model extraction: Attackers create offline copies of the model by repeatedly querying it to observe its functionality. Ineffective data security measures display their application programming interface (API), enabling greater risks for model extraction. An attacker can deeply analyze the offline copy and understand how to bypass the production model.
Model evasion: The attacker provides model input intentionally for models to produce incorrect decisions. Attackers observe the model's functionality and study how to bypass it. An attacker can trick AI-based anti-malware systems into not detecting their samples or bypass biometric verification systems.
Attackers are getting used to digital adoption efforts in industries. Emerging cyber attacks are becoming as common as traditional attacks like SQL injections. Penetration testers can incorporate strategies to mitigate these challenges into current penetration testing practices.
More in News