2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health...

45
Digital New Deal Technology Essentials 디지털 뉴딜 기술 핵심 IT 21 Global Conference 2020 Session 5-1 AI를 속이는 보안 공격과 대응 방안 연구 최대선 교수 (숭실대학교) [요약문] AI 기술이 다양한 분야에 적용되어 활용되고 있다. 정보보호 분야에서도 AI 기술을 악성코드 탐지, 침입탐지, 이상거래 탐지 등에 활용하고 있다. 그런데, AI를 대상으로 하는 여러 가지 보안 공격이 존재하며, 데이터에 간단한 변경을 가해서 AI를 속이고 오분류를 유도하는 기만공격이 심각한 문제로 부각되고 있다. 본 발표에서는 AI를 속이는 보안 공격의 다양한 형태와 실제 연구 결과를 소개한다. 얼굴인식기를 속이는 공격, 음성인식을 속이는 공격 등의 실제 원리와 효과를 살펴본 다. 또한, 이에 대한 기술적, 절차적 보안 대책의 현황을 살펴본다. 실제 상기 공격에 대응하는 연구 내용과 결과를 소개한다. [발표자 약력] 2009년 KAIST 전산학과 박사 1999년~2015년 ETRI 정보보호연구본부 인증기술연구실장 2015년~2020년8월 공주대학교 의료정보학과 교수 2020년9월~현재 숭실대학교 소프트웨어학부 교수 2019년~현재 한국정보보호학회 차세대인증연구회장 관심분야 : 정보보호, 사용자 인증, 인공지능 보안, 프라이버시 등

Transcript of 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health...

Page 1: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

Digital New Deal Technology Essentials

디지털 뉴딜 기술 핵심

IT21Global Conference2020

Session 5-1

AI를 속이는 보안 공격과 대응 방안 연구

최대선 교수 (숭실대학교)

[요약문]

AI 기술이 다양한 분야에 적용되어 활용되고 있다. 정보보호 분야에서도 AI 기술을 악성코드 탐지, 침입탐지, 이상거래 탐지 등에 활용하고 있다.

그런데, AI를 대상으로 하는 여러 가지 보안 공격이 존재하며, 데이터에 간단한 변경을 가해서 AI를 속이고 오분류를 유도하는 기만공격이 심각한 문제로 부각되고 있다.

본 발표에서는 AI를 속이는 보안 공격의 다양한 형태와 실제 연구 결과를 소개한다. 얼굴인식기를 속이는 공격, 음성인식을 속이는 공격 등의 실제 원리와 효과를 살펴본

다. 또한, 이에 대한 기술적, 절차적 보안 대책의 현황을 살펴본다. 실제 상기 공격에 대응하는 연구 내용과 결과를 소개한다.

[발표자 약력]

2009년 KAIST 전산학과 박사

1999년~2015년 ETRI 정보보호연구본부 인증기술연구실장

2015년~2020년8월 공주대학교 의료정보학과 교수

2020년9월~현재 숭실대학교 소프트웨어학부 교수

2019년~현재 한국정보보호학회 차세대인증연구회장

관심분야 : 정보보호, 사용자 인증, 인공지능 보안, 프라이버시 등

Page 2: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 926 -

Page 3: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 927 -

Page 4: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 928 -

Page 5: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 929 -

Page 6: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 930 -

Page 7: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 931 -

Page 8: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 932 -

Page 9: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 933 -

Page 10: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 934 -

Page 11: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 935 -

Page 12: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 936 -

Page 13: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 937 -

Page 14: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 938 -

Page 15: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 939 -

Page 16: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 940 -

Page 17: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 941 -

Page 18: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 942 -

Page 19: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 943 -

Page 20: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 944 -

Page 21: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 945 -

Page 22: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 946 -

Page 23: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 947 -

Page 24: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 948 -

Page 25: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 949 -

Page 26: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 950 -

Page 27: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 951 -

Page 28: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 952 -

Page 29: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 953 -

Page 30: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 954 -

Page 31: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 955 -

Page 32: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 956 -

Page 33: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 957 -

Page 34: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 958 -

Page 35: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 959 -

Page 36: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 960 -

Page 37: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 961 -

Page 38: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 962 -

Page 39: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 963 -

Page 40: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 964 -

Page 41: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 965 -

Page 42: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 966 -

Page 43: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 967 -

Page 44: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 968 -

Page 45: 2020 IT21 · 2020. 9. 23. · Systematic Poisoning Attacks„ IEEE Journal Of Bio & Health Informatics) MODEL EXTRACTION ATTACK OHN f 011 Inversion attack, Poisoning attack, Evasion

- 969 -