USENIX Security2024Top-tier venue
Towards More Practical Threat Models in Artificial Intelligence Security
Kathrin Grosse, Lukas Bieringer, Tarek R. Besold, Alexandre Alahi
Abstract
Recent works have identified a gap between research and practice in artificial intelligence security: threats studied in academia do not always reflect the practical use and security risks of AI. For example, while models are often studied in isolation, they form part of larger ML pipelines in practice. Recent works also brought forward that adversarial manipulations introduced by academic attacks are impractical. We take a first step towards describing the full extent of this disparity. To this end, we revisit the threat models of the six most studied attacks in AI security research and match them to AI usage in practice via a survey with 271 industrial practitioners. On the one hand, we find that all existing threat models are indeed applicable. On the other hand, there are significant mismatches: research is often too generous with the attacker, assuming access to information not frequently available in real-world settings. Our paper is thus a call for action to study more practical threat models in artificial intelligence security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers7
- Precise In-Parameter Concept Erasure in Large Language ModelsYoav Gur-Arieh, Clara Suslik, Yihuai Hong, Fazl Barez et al.EMNLP 2025 · 10 citations
- CRISP: Persistent Concept Unlearning via Sparse AutoencodersTomer Ashuach, Dana Arad, Aaron Mueller, Martin Tutek et al.ACL 2026 · 7 citations
- Backdoor Mitigation via Invertible Pruning MasksKealan Dunnett, Reza Arablouei, Volkan Dedeoglu, Dimity Miller et al.NeurIPS 2025 · 3 citations
- Achieving Zen: Combining Mathematical and Programmatic Deep Learning Model Representations for Attribution and ReuseDavid Oygenblik, Dinko Dermendzhiev, Filippos Sofias, Mingxuan Yao et al.NDSS 2026 · 1 citation
- DIPBox: A Multi-scale Testing Framework for Tracking Dataset RegenerationTian Dong, Yan Meng, Shaofeng Li, Guoxing Chen et al.CCS 2026
Builds on17
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter et al.USENIX Security 2016 · 2,088 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Label-Only Membership Inference AttacksChristopher A. Choquette-Choo, Florian Tramèr, Nicholas Carlini, Nicolas PapernotICML 2021 · 628 citations
- LIRA: Learnable, Imperceptible and Robust Backdoor AttacksKhoa D. Doan, Yingjie Lao, Weijie Zhao, Ping LiICCV 2021 · 313 citations
- Witches' Brew: Industrial Scale Data Poisoning via Gradient MatchingJonas Geiping, Liam H. Fowl, W. Ronny Huang, Wojciech Czaja et al.ICLR 2021 · 268 citations
Related papers
- "Abuse Risks are Often Inherent to Product Features": Exploring AI Vendors' Bug Bounty and Responsible Disclosure PoliciesYangheran Piao, Jingjie Li, Daniel W. WoodsUSENIX Security 2026 · 1 citation
- SoK: All You Need to Know About On-Device ML Model Extraction - The Gap Between Research and PracticeTushar Nayan, Qiming Guo, Mohammed Alduniawi, Marcus Botacin et al.USENIX Security 2024 · 20 citations
- Securing the AI Supply Chain: What Can We Learn From Developer-Reported Security Issues and Solutions of AI Projects?The Anh Nguyen, Triet Huynh Minh Le, M. Ali BabarICSE 2026 · 1 citation
- On The Empirical Effectiveness of Unrealistic Adversarial Hardening Against Realistic Adversarial AttacksSalijona Dyrmishi, Salah Ghamizi, Thibault Simonetto, Yves Le Traon et al.S&P 2023
- Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning AttacksAvi Schwarzschild, Micah Goldblum, Arjun Gupta, John P. Dickerson et al.ICML 2021 · 207 citations
