[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-122644-en":3,"doc-seo-122644-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},122644,687197100911,"Himbo","https://ap-avatar.wpscdn.com/avatar/a000239b6f1da00475?x-image-process=image/resize,m_fixed,w_180,h_180&k=1785132997149421697",8,"Research & Report","Measuring Equality in Machine Learning Security Defenses - Case Study in Speech Recognition","Over the past decade, machine learning security research has produced many defenses against evasion attacks, yet it often leaves unclear who benefits from these protections. This work connects security defenses with fairness parity metrics to evaluate performance inequities across sub-populations. Using empirical case study results, it shows that common defenses can cause harms such as false rejection and unequal benefits from robustness training. The proposed framework supports multiple defense types and identifies dataset sets for user-centered measurement, including speech recognition results across gender, accent, and age.","Measuring Equality in Machine Learning Security  \nDefenses  \nLuke E. Richardsa, b; * , Edward Raffa, c and Cynthia Matuszeka  \naUniversity of Maryland, Baltimore County  \nb Pacific Northwest National Laboratory  \ncBooz Allen Hamilton  \narXiv :2302 .08973v 5 [ cs .LG] 1 Jun 2023  \nAbstract. Over the past decade, the machine learning security community has developed myriad defenses for evasion attacks. An understudied question in that community is: for whom do these defenses defend? This work considers common approaches to defending learned systems and how security defenses result in performance inequities across different sub-populations. We outline appropriate parity metrics for analysis and begin to answer this question through empirical results of the fairness implications of machine learning security methods. We find that many methods that have been proposed can cause direct harm, like false rejection and unequal benefits from robustness training. The framework we propose for measuring defense equality can be applied to robustly trained models, preprocessing-based defenses, and rejection methods. We identify a set of datasets with a user-centered application and a reasonable computational cost suitable for case studies in measuring the equality of defenses. In our case study of speech command recognition, we show how such adversarial training and augmentation have non-equal but complex protections for social subgroups across gender, accent, and age in relation to user coverage. We present a comparison of equality between two rejection-based defenses: randomized smoothing and neural rejection, finding randomized smoothing more equitable due to the sampling mechanism for minority groups. This represents the first work examining the disparity in the adversarial robustness in the speech domain and the fairness evaluation of rejection-based defenses.  \n1 Introduction  \nSystems integrating machine learning (ML) introduce a new attack surface for adversaries to take advantage of regarding security. So far, we observe that when developing defenses for these systems, only a few works take any metric beyond the increase in robustness to attack account at a high level. However, these systems are rarely considered when designed to interact with humans. In a field where many defenses are already not adequately evaluated, leading to a false sense of security [6], such user-centric evaluations should also be at the forefront. In this work, we expand on the measurement of security ina user-centric manner.  \nWe do this by examining the broader set of defenses being introduced in machine learning systems. These include defenses that exist outside of the model weights themselves, like preprocessing and postprocessing. We integrate concepts of parity studied by the machine learning fairness community which measures the equality of performance or outcomes resulting from such a system. Through  \n∗ Corresponding Author. Email: [lerichards@umbc.edu](lerichards@umbc.edu).  \nthis intersectional view, we seek to aid the understanding of the questions the community should ask when integrating various defense defenses. Broadly, this question presents itself: who do these proposed defenses work for when the system is under attack and when not?  \nThis comes at a time when machine learning security is being recognized and reaching the maturity of deployment in the private and public sectors. While there exist many complex threat models and levels of access in the literature, we examine impact-based attacks where a defender would attempt to protect the system from potential adversarial inputs. This type of attack represents a level of access only at test time rather than the development of the model. Commonly, the success criteria of an introduced defense are high performance with and without the presence of an attack. In this work, we expand this success criterion to ensure the defenses work for many different user demographics with and without attack.  \n","cbCailISymu1Vrrg","https://ap.wps.com/l/cbCailISymu1Vrrg","pdf",1196533,1,11,"English","en",105,"# Introduction\n## User-centric defense evaluation\n## Parity metrics and disparate impact\n## Case study motivation and safety context\n## Metrics for robustness training and rejection defenses","[{\"question\":\"What question does the paper focus on regarding machine learning security defenses?\",\"answer\":\"It asks for whom these defenses provide protection. Specifically, it evaluates whether security methods create performance inequities across different sub-populations.\"},{\"question\":\"What kinds of harm do the authors find in many proposed defenses?\",\"answer\":\"The work reports that some methods can directly harm users through false rejection and unequal benefits from robustness training.\"},{\"question\":\"How does the speech recognition case study evaluate equality of defenses?\",\"answer\":\"It measures how adversarial training and augmentation yield non-equal but complex protections across social subgroups defined by gender, accent, and age, and it compares randomized smoothing with neural rejection.\"}]","Measuring Equality in Machine Learning Security Defenses - Case Study in Speech Recognition | PDF",1785811896,28,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"measuring-equality-in-machine-learning-security-defenses-case-study-in-speech-recognition","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/measuring-equality-in-machine-learning-security-defenses-case-study-in-speech-recognition/122644/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What question does the paper focus on regarding machine learning security defenses?","Question",{"text":75,"@type":76},"It asks for whom these defenses provide protection. Specifically, it evaluates whether security methods create performance inequities across different sub-populations.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What kinds of harm do the authors find in many proposed defenses?",{"text":80,"@type":76},"The work reports that some methods can directly harm users through false rejection and unequal benefits from robustness training.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the speech recognition case study evaluate equality of defenses?",{"text":84,"@type":76},"It measures how adversarial training and augmentation yield non-equal but complex protections across social subgroups defined by gender, accent, and age, and it compares randomized smoothing with neural rejection.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]