[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-116827-en":3,"doc-seo-116827-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},116827,1099513958607,"Jiven","https://ap-avatar.wpscdn.com/avatar/100002390cf8733938c?x-image-process=image/resize,m_fixed,w_180,h_180&k=1778829742770036399",8,"Research & Report","Why do so? - A Practical Perspective on Machine Learning Security","Despite extensive academic work on machine learning security, attack occurrences in real deployments remain poorly understood. This paper presents a quantitative study with 139 industrial practitioners to analyze how often attacks arise, how strongly practitioners perceive threats, and which factors shape threat exposure and defense practices. Organizational and individual patterns are examined, including how prior ML security knowledge influences perception. Detailed responses highlight concerns such as unreliable decision making, business information leakage, and bias introduction, informing regulation and auditing.","“Why do so?”—A Practical Perspective on Machine Learning Security  \nKathrin Grosse, Lukas Bieringer, Tarek R. Besold, Battista Biggio, Senior Member, IEEE, Katharina Krombholz  \narXiv :2207 .05 164v 1 [ cs .LG] 11 Jul 2022  \nAbstract—Despite the large body of academic work on machine learning security, little is known about the occurrence of attackson machine learning systems in the wild. In this paper, wereport on a quantitative study with 139 industrial practitioners. We analyze attack occurrence and concern and evaluate statistical hypotheses on factors inﬂuencing threat perception and exposure. Our results shed light on real-world attacks on deployed machine learning. On the organizational level, while we ﬁnd no predictors for threat exposure in our sample, the amount of implement defenses depends on exposure to threats or expected likelihood to become a target. We also provide a detailed analysis of practitioners' replies on the relevance of individual machine learning attacks, unveiling complex concerns like unreliable decision making, business information leakage, and bias introduction into models. Finally, we ﬁnd that on the individual level, prior knowledge about machine learning security inﬂuences threat perception. Our work paves the way for more research about adversarial machine learning in practice, but yields also insights for regulation and auditing.  \nIndex Terms—Adversarial Machine Learning, Machine Learning Security, Quantitative User Study.  \nI. INTRODUCTION  \nA large body of academic work focuses on machine learning security or adversarial machine learning (AML) [1]–[11] . These works investigate how machine learning (ML) can be circumvented and exploited by an attacker. For example, an attacker can tamper with the training data, yielding a model inferior in performance or that is sensitive to attacker speciﬁed, small parts of the input [4] . Alternatively, the attacker slightly alters tests data to change the output of an ML model [5],[10] . In addition, an ML model may leak the used training data [12] or can easily be copied when freely exposed [11] . Many of the settings studied AML can be criticized for being rather artiﬁcial. However, already these settings are hard to solve [4], [13] . One possible cause is that even though the current usage of ML in security and threat modelling have been criticised [14], [15], there is little work on ML security in the real world. The ﬁrst work in this direction, by Kumar et al. [16], investigated which AML threats are feared in practice and reported that industry is most concerned about poisoning attacks. Mirsky et al. [17] reported that organizations perceive 24 of 33 offensive AI techniques as a signiﬁcant threat. Moreover, Bieringer et al. [18] found evidence for rudimentary attacks on AI in the wild in their interviews among ML  \nFirst two authors contributed equally.  \nK. Grosse and B. Biggio are with the university of Cagliari. L. Bieringeris with QuantPi, T.R. Besold with Eindhoven University of Technology, K. Krombholz with CISPA Helmholtz Center of Information Security. B. Biggiois also with PluribusOne.  \nManuscript received April 19, 2005; revised August 26, 2015 .  \npractitioners. Boenisch et al. [19] ﬁnd that security and ML security awareness of ML practitioners was overall low.  \nTo shed light on the state of AML in practice and the factors inﬂuencing organizations' approach to ML security, we conduct a quantitative survey among ML practitioners. Inspired by prior work [17], we investigate which threats are dreaded and why. Furthermore, we control for variables like application area [19], how long ML has been used in production, data type, and prior knowledge [18] . All these questions and variables form part of our anonymous questionnaire for ML-practitioners. Our 139 participants help us to shed light on the following topics:  \nAML in practice. We ﬁnd that there are occurrences of AML attacks, more speciﬁcally evasion and poisoning, in practice. H","cbCaisbKZ1wUxj2W","https://ap.wps.com/l/cbCaisbKZ1wUxj2W","pdf",483763,1,18,"English","en",105,"# Introduction\n## AML threats studied in prior work\n## Motivation and survey design\n# Background","[{\"question\":\"What gap does the paper address in machine learning security research?\",\"answer\":\"It highlights that, despite many academic studies on ML security, there is limited knowledge about how attacks actually occur in real-world deployments. The paper focuses on evidence from industrial practitioners rather than purely theoretical settings.\"},{\"question\":\"How was the study conducted to understand AML in practice?\",\"answer\":\"The study uses a quantitative survey of 139 industrial machine learning practitioners. It collects responses about attack occurrences, threat concerns, and factors influencing threat perception and exposure.\"},{\"question\":\"Which factors influence threat perception and defense measures in the organizations studied?\",\"answer\":\"The findings suggest no predictors for threat exposure in the sample at the organizational level, while the number of implemented defenses depends on exposure to threats or the expected likelihood of becoming a target. On the individual level, prior knowledge about ML security affects threat perception.\"}]","Why do so? - A Practical Perspective on Machine Learning Security | PDF",1785671971,45,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"why-do-so-a-practical-perspective-on-machine-learning-security","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/why-do-so-a-practical-perspective-on-machine-learning-security/116827/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What gap does the paper address in machine learning security research?","Question",{"text":75,"@type":76},"It highlights that, despite many academic studies on ML security, there is limited knowledge about how attacks actually occur in real-world deployments. The paper focuses on evidence from industrial practitioners rather than purely theoretical settings.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How was the study conducted to understand AML in practice?",{"text":80,"@type":76},"The study uses a quantitative survey of 139 industrial machine learning practitioners. It collects responses about attack occurrences, threat concerns, and factors influencing threat perception and exposure.",{"name":82,"@type":73,"acceptedAnswer":83},"Which factors influence threat perception and defense measures in the organizations studied?",{"text":84,"@type":76},"The findings suggest no predictors for threat exposure in the sample at the organizational level, while the number of implemented defenses depends on exposure to threats or the expected likelihood of becoming a target. On the individual level, prior knowledge about ML security affects threat perception.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]