[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-123068-en":3,"doc-seo-123068-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},123068,8796095461610,"Oliver","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","RMF - A Risk Measurement Framework for Machine Learning Models","Machine learning (ML) models are increasingly deployed in safety- and security-critical applications, making security measurement essential. This paper develops a technical risk measurement framework for ML security, with emphasis on autonomous vehicles. Using ISO/IEC 27004:2016 as a basis, risk indicators quantify potential damage and the attacker’s required effort. Because a single risk value for attacker effort is not obtainable, four values are interpreted separately and evaluated via a case study.","RMF: A Risk Measurement Framework for Machine Learning  \nModels  \nJan Schröder  \n[schroeder.jan@protonmail.com](schroeder.jan@protonmail.com)[ ](schroeder.jan@protonmail.com)Fraunhofer FOKUS, HTW Berlin Berlin, Germany  \nJakub Breier  \n[jbreier@jbreier.com](jbreier@jbreier.com)[ ](jbreier@jbreier.com)TTControl GmbH Vienna, Austria  \narXiv :2406 . 12929v1 [ cs .CR] 15 Jun 2024  \nABSTRACT  \nMachine learning (ML) models are used in many safety-and securitycritical applications nowadays. It is therefore important to measure the security of a system that uses ML as a component. This paper focuses on the field of ML, particularly the security of autonomous vehicles. For this purpose, a technical framework will be described, implemented, and evaluated in a case study. Based on ISO/IEC 27004:2016, risk indicators are utilized to measure and evaluate the extent of damage and the effort required by an attacker. It isnot possible, however, to determine a single risk value that represents the attacker’s effort. Therefore, four different values must be interpreted individually.  \nCCS CONCEPTS  \n• Security and privacy → Software security engineering.  \nKEYWORDS  \nMachine Learning Security, ISO/IEC 27004:2016, Risk Measurement, Backdoor Attacks, Adversarial Machine Learning  \nACM Reference Format:  \nJan Schröder and Jakub Breier. 2024. RMF: A Risk Measurement Framework for Machine Learning Models. In The 19th International Conference on Availability, Reliability and Security (ARES 2024), July 30-August 2, 2024, Vienna, Austria. ACM, New York, NY, USA, 6 pages. [https://doi.org/10.1145/](https://doi.org/10.1145/)[ ](https://doi.org/10.1145/)nnnnnnn.nnnnnnn  \n1 INTRODUCTION  \nMachine learning (ML), especially deep learning, is currently one of the most popular subjects in computer science. As the popularity of ML increases, so does the risk of adversarial machine learning [15]—the risk of neural networks (NN) being influenced maliciously. The security of ML is especially relevant in safety-critical areas such as medical imaging diagnosis, automated driving, and connected and cooperative mobile machinery.  \nIn this paper, we focus on measuring poisoning attacks that misclassify the labels of images in NN and the effort required by the attacker to execute the attack. We use the term \"measurements\"to refer to the recording of the process, detailing what an attacker needs to do and what resources they need to perform their specific attack. For a better understanding of the measurement process, a case study demonstrates a concrete example involving the classification of road signs for autonomous vehicles. This measurement computes the risk involved with a poisoning attack and evaluates the effort required by an attacker.  \nARES 2024, July 30-August 2, 2024, Vienna, Austria 2024. ACM ISBN 979-8-4007-1718-5/24/07. . . $15.00 [https://doi.org/10.1145/nnnnnnn.nnnnnnn](https://doi.org/10.1145/nnnnnnn.nnnnnnn)  \nThe measurement of poisoning attacks leads to the following questions: How much damage is possible with an attack against a NN? What is the minimum effort an attacker needs to invest to achieve predefined damage? The objective of this paper is to devise a framework for quantifying the extent of damage and the attacker’s effort in order to derive a risk value that describes the level of risk associated with adversarial attacks against NN. This risk level is intended to describe how significant the risk is when an attack is executed, depending on whether the attacker has a low or high effort. The proposed framework should take into account the requirements specified by the ISO/IEC 27004:2016 standard as accurately as possible for measuring information security risk. Our Contribution. This paper follows the requirements of ISO/IEC 27004:2016 [1] and provides the following contributions:  \n(1) We propose quantitative and qualitative attributes that should be instantiated with data during measurement methods.  \n(2) We develop measurement functions to ","cbCaic92FFgro5TN","https://ap.wps.com/l/cbCaic92FFgro5TN","pdf",515716,1,6,"English","en",105,"# Introduction\n# Background and Related Work\n## Adversarial Attacks on Neural Networks\n## Backdoor Attacks","[{\"question\":\"What security risk does the paper focus on measuring for ML models?\",\"answer\":\"The paper focuses on measuring poisoning attacks that misclassify image labels in neural networks and on quantifying the effort required by an attacker to execute the attack.\"},{\"question\":\"Which standard does the proposed framework follow?\",\"answer\":\"The framework is based on ISO/IEC 27004:2016 and uses risk indicators to measure and evaluate the extent of damage and attacker effort.\"},{\"question\":\"Why does the framework use multiple values instead of a single risk value?\",\"answer\":\"It is not possible to determine one risk value representing the attacker’s effort, so four different values are computed and interpreted individually.\"}]","RMF - A Risk Measurement Framework for Machine Learning Models | PDF",1785814487,15,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"rmf-a-risk-measurement-framework-for-machine-learning-models","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/rmf-a-risk-measurement-framework-for-machine-learning-models/123068/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What security risk does the paper focus on measuring for ML models?","Question",{"text":75,"@type":76},"The paper focuses on measuring poisoning attacks that misclassify image labels in neural networks and on quantifying the effort required by an attacker to execute the attack.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Which standard does the proposed framework follow?",{"text":80,"@type":76},"The framework is based on ISO/IEC 27004:2016 and uses risk indicators to measure and evaluate the extent of damage and attacker effort.",{"name":82,"@type":73,"acceptedAnswer":83},"Why does the framework use multiple values instead of a single risk value?",{"text":84,"@type":76},"It is not possible to determine one risk value representing the attacker’s effort, so four different values are computed and interpreted individually.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,114,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]