[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118119-en":3,"doc-seo-118119-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118119,5909877438554,"Maeve","https://ap-avatar.wpscdn.com/avatar/5600025385ad2bf12a7?_k=1778553567797529272",8,"Research & Report","Machine learning security and privacy - a review of threats and countermeasures","Machine learning security and privacy are critical as intelligent digital solutions increasingly support daily activities, from disease diagnosis and autonomous vehicles to automated threat detection and triage. The use of machine learning in smart grids, transport, and natural resources enlarges the attack surface for adversaries who can reverse engineer publicly available models. An in-depth analysis reviews key threats, attack development factors, interrelated attack chains, and mitigation methods, including data sanitization, adversarial training, and differential privacy, noting their practical limitations. Attack-surface and countermeasure insights guide directions to improve trustworthiness.","Paracha et al.  \nEURASIP Journal on Information Security (2024) 2024:10  \n[https://doi.org/10.1186/s13635-024-00158-3](https://doi.org/10.1186/s13635-024-00158-3)  \nEURASIP Journal on Information Security  \n REVIEW Open Access  \nMachine learning security and privacy: a review of threats and countermeasures  \nAnum Paracha 1*, Junaid Arshad1, Mohamed Ben Farah 1 and Khalid Ismail 1  \nAbstract  \nMachine learning has become prevalent in transforming diverse aspects of our daily lives through intelligent digital solutions. Advanced disease diagnosis, autonomous vehicular systems, and automated threat detection and triage are some prominent use cases. Furthermore, the increasing use of machine learning in critical national infrastructures such as smart grids, transport, and natural resources makes it an attractive target for adversaries. The threat to machine learning systems is aggravated due to the ability of mal-actors to reverse engineer publicly available models, gaining insight into the algorithms underpinning these models. Focusing on the threat landscape for machine learning systems, we have conducted an in-depth analysis to critically examine the security and privacy threats to machine learning and the factors involved in developing these adversarial attacks. Our analysis highlighted that feature engineering, model architecture, and targeted system knowledge are crucial aspects in formulating these attacks. Furthermore, one successful attack can lead to other attacks; for instance, poisoning attacks can lead to membership inference and backdoor attacks. We have also reviewed the literature concerning methods and techniques to mitigate these threats whilst identifying their limitations including data sanitization, adversarial training, and differential privacy. Cleaning and sanitizing datasets may lead to other challenges, including underfitting and affecting model performance, whereas differential privacy does not completely preserve model’s privacy. Leveraging the analysis of attack surfaces and mitigation techniques, we identify potential research directions to improve the trustworthiness of machine learning systems.  \nKeywords Adversarial attacks, Scrutiny-by-design, Poisoned dataset, Exploiting integrity, Data sanitization, Differential privacy  \n1 Introduction  \nMachine learning underpins significant advancementsin the digital era by automating systems and making solutions autonomous and self-learned [1, 2]. Examples include facial recognition systems [3, 4], spam-filtering systems [5, 6], securing autonomous vehicle and IoT systems [7–9], and intelligent firewalls [10, 11] which puts forward the need for its security evaluation and robustness against adversarial machine learning (AML) attacks.  \n*Correspondence:  \nAnum Paracha [anum.paracha@mail.bcu.ac.uk](anum.paracha@mail.bcu.ac.uk)  \n1 School of Computing and Digital Technology, Birmingham City University, Birmingham, UK  \nAdversaries considerably manipulate machine learning to degrade the victim’s performance, inject a backdoor, or exploit its privacy, specifically targeting security-sensitive applications [12] to disrupt their integrity or secrecy.  \nBreaching integrity by manipulating training datasets or model parameters is a poisoning attack. Some existing poisoning attacks are feature collision attacks [13], convex polytope attacks [14], random label flipping attacks [15, 16], and fast gradient sign method (FGSM) attack [17] . Manipulating the testing dataset isan evasion attack [18, 19] . Simultaneously, the privacy of the ML models can be exploited with model inversion or inference attacks to either reveal the parameters of the targeted model or extrapolate manipulated data to infer the expected output to analyze and assess the  \n© The Author(s) 2024. Open Access This article is licensed under a Creative Commons Attribution 4.0 International License, which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as yo","cbCaitAv1lewaL2O","https://ap.wps.com/l/cbCaitAv1lewaL2O","pdf",2810357,1,23,"English","en",105,"# Introduction\n## Threats and attack types\n## Privacy and inference attacks\n## Mitigation techniques and limitations\n## Research directions","[{\"question\":\"Why are machine learning security and privacy major concerns in real-world systems?\",\"answer\":\"Machine learning is widely used in safety- and infrastructure-critical applications, making it an attractive target. Adversaries can also reverse engineer models and exploit vulnerabilities affecting integrity and secrecy.\"},{\"question\":\"What are the main adversarial attack types discussed in the review?\",\"answer\":\"The review compares poisoning, evasion, model inversion, and membership inference attacks. It also highlights how poisoning can enable follow-on attacks such as membership inference and backdoors.\"},{\"question\":\"Which mitigation approaches are reviewed, and what limitations are noted?\",\"answer\":\"Mitigation methods include data sanitization, adversarial training, and differential privacy. Dataset cleaning may harm performance or cause underfitting, while differential privacy does not fully preserve privacy.\"}]","Machine learning security and privacy - a review of threats and countermeasures | PDF",1785681704,58,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"machine-learning-security-and-privacy-a-review-of-threats-and-countermeasures","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/machine-learning-security-and-privacy-a-review-of-threats-and-countermeasures/118119/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why are machine learning security and privacy major concerns in real-world systems?","Question",{"text":75,"@type":76},"Machine learning is widely used in safety- and infrastructure-critical applications, making it an attractive target. Adversaries can also reverse engineer models and exploit vulnerabilities affecting integrity and secrecy.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What are the main adversarial attack types discussed in the review?",{"text":80,"@type":76},"The review compares poisoning, evasion, model inversion, and membership inference attacks. It also highlights how poisoning can enable follow-on attacks such as membership inference and backdoors.",{"name":82,"@type":73,"acceptedAnswer":83},"Which mitigation approaches are reviewed, and what limitations are noted?",{"text":84,"@type":76},"Mitigation methods include data sanitization, adversarial training, and differential privacy. Dataset cleaning may harm performance or cause underfitting, while differential privacy does not fully preserve privacy.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]