[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-122534-en":3,"doc-seo-122534-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},122534,1099514068365,"Aurelia","https://ap-avatar.wpscdn.com/avatar/10000253d8d9f28188e?_k=1776742907772140068",8,"Research & Report","TA3 - Testing Against Adversarial Attacks on Machine Learning Models - interactive system for HITL","Adversarial attacks pose major risks to deploying machine learning models across real-world applications. Testing models against such attacks is therefore essential for both evaluation and improvement. This paper presents the design and development of TA3, an interactive, human-in-the-loop system that enables human-steered attack simulation and visualization-assisted assessment of attack impact. The current version focuses on testing decision tree models using the One Pixel Attack method, highlighting HITL’s value and extending its potential to broader ML models and adversarial attack types.","TA3: Testing Against Adversarial Attacks on Machine Learning Models  \nYuanzhe Jin  \nDepartment of Engineering Science University of Oxford Oxford, United Kingdom [yuanzhe.jin@eng.ox.ac.uk](yuanzhe.jin@eng.ox.ac.uk)  \nMin Chen  \nDepartment of Engineering Science University of Oxford Oxford, United Kingdom [min.chen@oerc.ox.ac.uk](min.chen@oerc.ox.ac.uk)  \narXiv :2410 .05334v 1 [ cs .CR] 6 Oct 2024  \nAbstract—Adversarial attacks are major threats to the deployment of machine learning (ML) models in many applications. Testing ML models against such attacks is becoming an essential step for evaluating and improving ML models. In this paper, we report the design and development of an interactive system for aiding the workflow of Testing Against Adversarial Attacks (TA3). In particular, with TA3, human-in-the-loop (HITL) enables human-steered attack simulation and visualization-assisted attack impact evaluation. While the current version of TA3 focuses on testing decision tree models against adversarial attacks based on the One Pixel Attack Method, it demonstrates the importance of HITL in ML testing and the potential application of HITL to the ML testing workflows for other types of ML models and other types of adversarial attacks.  \nIndex Terms—Machine learning, decision tree, adversarial attack, visual analysis, model testing, interactive testing.  \nI. INTRODUCTION  \nThe rapid development of machine learning (ML) technology has started to bring forth the deployment of ML models in our daily lives, e.g., face recognition, traffic management, unmanned supermarkets, and autonomous vehicles. At the same time, the quality of ML models has received increasing attention. Research on adversarial attacks has discovered a variety of vulnerabilities in ML models, ranging from getting a model to mistake a panda for a gibbon [1] to getting Tesla’s self-driving car to misjudge the speed limit sign [2] . In the field of ML, the current research effort on adversarial attacks places the main emphasis on discovering new adversarial attack methods and improving ML models’ resistance against specific types of adversarial attacks. The former has resulted in a large collection of attacking methods [3], while the latter typically focuses on the training processes, e.g., data distill [4] and adversarial training [5] . In this work, we focus on ML testing processes against adversarial attacks.  \nThere are differences as well as similarities between testing ML models and testing conventional software. The main differences include (i) deployable ML models are expected to make mistakes while deployable conventional software is expected to be bug-free; (ii) the inner workings of an ML model are expected to be difficult to comprehend, while a handcrafted program is expected to be fully understood. Because of these differences, the testing of ML models has relied primarily on statistical measures resulting from automated test runs, while  \nthe testing workflows for conventional software have relied extensively on human-in-the-loop (HITL) . Fundamentally, an ML model is also a program. Similar to a handcrafted program, the search space for a potential error in these programs is huge in that relying on a fully automated process to search for errors is mostly intractable computationally. Hence, in conventional software testing, HITL allows human experts to inject their knowledge to focus on highly probable parts of the search space. There is no reason why HITL cannot help human experts in testing ML models. This reasoning motivates us to develop an interactive software system to support ML testing workflows against adversarial attacks.  \nThere is a large collection of attacking methods, many of which apply to models trained with a specific algorithmic framework and specific types of training data [6] . There are also several strategies for defending against adversarial attacks, such as threat modeling, attack simulation, attack impact evaluation, countermeasure d","cbCaidvzTix37J0R","https://ap.wps.com/l/cbCaidvzTix37J0R","pdf",2932380,1,15,"English","en",105,"# Introduction\n## Motivation and differences from conventional software testing\n## Related defense and evaluation strategies\n# Related Work\n## Human-centered Artificial Intelligence","[{\"question\":\"What problem does TA3 address in machine learning security?\",\"answer\":\"TA3 targets the need to test machine learning models against adversarial attacks before deployment, enabling evaluation and improvement of model robustness.\"},{\"question\":\"How does TA3 support testing workflows?\",\"answer\":\"TA3 uses human-in-the-loop control to steer adversarial attack simulation and provides visualization to assess attack impact and model weaknesses beyond statistical summaries.\"},{\"question\":\"What does the current TA3 version focus on?\",\"answer\":\"The current TA3 version tests decision tree models against adversarial attacks generated via the One Pixel Attack method.\"}]","TA3 - Testing Against Adversarial Attacks on Machine Learning Models - interactive system for HITL | PDF",1785811133,38,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"ta3-testing-against-adversarial-attacks-on-machine-learning-models-interactive-system-for-hitl","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/ta3-testing-against-adversarial-attacks-on-machine-learning-models-interactive-system-for-hitl/122534/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does TA3 address in machine learning security?","Question",{"text":75,"@type":76},"TA3 targets the need to test machine learning models against adversarial attacks before deployment, enabling evaluation and improvement of model robustness.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does TA3 support testing workflows?",{"text":80,"@type":76},"TA3 uses human-in-the-loop control to steer adversarial attack simulation and provides visualization to assess attack impact and model weaknesses beyond statistical summaries.",{"name":82,"@type":73,"acceptedAnswer":83},"What does the current TA3 version focus on?",{"text":84,"@type":76},"The current TA3 version tests decision tree models against adversarial attacks generated via the One Pixel Attack method.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]