Method for evaluating the industrial systems with built-in artificial intelligence robustness to adversarial attacks

DOI: 10.21293/1818-0442-2023-26-4-44-52

Download article in PDF format

JATS xml

Abstract: The paper presents a method for evaluating the industrial systems with built-in artificial intelligence (AI) robustness to adversarial attacks. The influence of adversarial attacks on the systems performance has been studied. The scheme and the scenarios to implement attacks on industrial systems with built-in AI were presented. A comprehensive set of metrics used to study the robustness of ML models has been proposed, including test data set quality metrics (MDQ), ML model quality metrics (MMQ), and model robustness to adversarial attacks metrics (MSQ). The method is based on the use of this metrics set and includes the following steps: generating a set of test data containing clean samples; assessing the quality of a test data set using MMQ metrics; identification of relevant adversarial attacks methods; generating adversarial examples and a test data set, containing the adversarial samples, to evaluate the robustness of the ML model; assessing the quality of the generated adversarial test data set using MDQ indicators; evaluating the quality of a ML model using MMQ indicators; evaluating model robustness using MSQ scores.

Keywords: cybersecurity, artificial intelligence methods, intelligent production systems, adversarial attacks

Funding: The work was carried out with the support of the Ministry of Science and Higher Education of the Russian Federation, No. 2019-0898.

For citation:
Vorobieva A. A. Method for evaluating the industrial systems with built-in artificial intelligence robustness to adversarial attacks. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2023, vol. 26, no. 4, pp. 44–52. DOI: 10.21293/1818-0442-2023-26-4-44-52

Authors and copyright holders:

  • Vorobieva A. A. , National-Research-Itmo-University-(st.-Petersburg,-Russia)

  • 1. Okruzhnov A.V, Khaibunasov R.R., Khasanov I.R., Andreeva M.M. [Overview of the modern market for distributed control systems in the oil and gas industry]. Bulletin of the Technological University, 2015, vol. 18, no. 1, pp. 383–389 (in Russ.).
  • 2. Koekin V.A. Control algorithms for geographically distributed industrial and domestic facilities. Electrical Engineering and Information Complexes and Systems, 2008, no. S1, pp. 59–65 (in Russ.).
  • 3. Vorobeva A.A., Fedosenko M.Yu. Methods for data mining and natural language processing in the management of robotic production systems. Proceedings of TUSUR University, 2023, vol. 26, no. 3, pp. 65-71.
  • 4. Smart Factory Monitoring. Available at: https://www.procemex.com/smart-factory/, free (Accessed: December 02, 2023).
  • 5. AIoT for smart factories. Available at: https://www.cta.ru/articles/obzory/vstraivaemye-sistemy/165894/, free (Accessed: December 02, 2023).
  • 6. Adversarial/Robust AI Report development methodology. Available at: https://ec.europa.eu/research/participants/documents/downloadPublic?documentIds=080166e5e1fdef06&appId=PPGMS, free (Accessed: December 02, 2023).
  • 7. Kong Z., Xue J., Wang Y., Huang L., Niu Z., Li F. A survey on adversarial attack in the age of artificial intelligence, Wireless Communications and Mobile Computing, 2021, vol. 2021, pp. 1–22.
  • 8. Xu J., Kovatsch M., Mattern D., Mazza F., Harasic M., Paschke A., Lucia S. A review on ai for smart manufacturing: Deep learning challenges and solutions, Applied Sciences, 2022, vol. 12, no. 16, pp. 8239.
  • 9. Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations. Available at: https://csrc.nist.gov/pubs/ai/100/2/e2023/ipd, free (Accessed: December 02, 2023).
  • 10. Goodfellow I.J., Shlens J., Szegedy C. Explaining and harnessing adversarial examples. Available at: https://arxiv.org/abs/1412.6572, free (Accessed: December 02, 2023).
  • 11. Tuptuk N., Hailes S. Security of smart manufacturing systems, Journal of Manufacturing Systems, 2018, vol. 47, pp. 93–106.
  • 12. Zolfi A., Avidan S., Elovici Y., Shabtai A. Adversarial Mask: Real-World Universal Adversarial Attack on Face Recognition Model, Joint European Conference on Machine Learning and Knowledge Discovery in Databases, 2022, pp. 304–320.
  • 13. Zhang Y., Zhang Yi., Qi J., Bin K., Wen H., Tong X. Adversarial patch attack on multi-scale object detection for UAV remote sensing images, Remote Sensing, 2022, vol. 14, no. 21, pp. 5298.
  • 14. Zhang S., Cheng Y., Zhu W., Ji X., Xu W. {CAPatch}: Physical Adversarial Patch against Image Captioning Systems, 32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 679–696.
  • 15. Jia Y., Poskitt C.M., Sun J., Chattopadhyay S. Physical Adversarial Attack on a Robotic Arm, IEEE Robotics and Automation Letters, 2022, vol. 7, no. 4, pp. 9334–9341.
  • 16. Kong X., Ge Z. Adversarial attacks on neural-network-based soft sensors: Directly attack output, IEEE Transactions on Industrial Informatics, 2021, vol. 18, no. 4, pp. 2443–2451.
  • 17. Dorf R., Bishop R. Sovremennye sistemy upravleniya [Modern control systems]. Moskva, Laboratoriya Bazovyh Znanij, 2002, 832 p. (in Russ.).
  • 18. Ma L., Juefei-Xu F., Zhang F., Sun J., Xue M., Li B., Chen C. Deepgauge: Multi-granularity testing criteria for deep learning systems, Proceedings of the 33rd ACM/IEEE International Conference on Automated Software Engineering, 2018, pp. 120–131.
  • 19. Guo J., Bao W., Wang J., Ma Y., Gao X., Xiao G., Liu A. A comprehensive evaluation framework for deep model robustness, Pattern Recognition, 2023, vol. 137, pp. 109308.
  • 20. Yang Y., Huang P., Cao J., Ma F., Zhang J., Li J. Quantifying Robustness to Adversarial Word Substitutions, Joint European Conference on Machine Learning and Knowledge Discovery in Databases, 2023, pp. 95–112.
  • 21. Luo B., Liu Y., Wei L., Xu Q. Towards imperceptible and robust adversarial example attacks against neural networks, Proceedings of the AAAI Conference on Artificial Intelligence, 2018, vol. 32, no. 1, pp 1–8.
  • 22. Hendrycks D., Dietterich T. Benchmarking neural network robustness to common corruptions and perturbations. Available at: https://arxiv.org/abs/1903.12261, free (Accessed: December 02, 2023).
Editorial office address

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 701-582

  journal@tusur.ru

 

Viktor N. Maslennikov

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02

Subscription for updates