A Genetic Attack Against Machine Learning Classifiers to Steal Biometric Actigraphy Profiles from Health Related Sensor Data.
In this work, we propose the use of a genetic-algorithm-based attack against machine learning classifiers with the aim of 'stealing' users' biometric actigraphy profiles from health related sensor data. The target classification model uses daily actigraphy patterns for user identification. The biome...
| Publicado en: | Journal of Medical Systems Vol. 44; no. 10 |
|---|---|
| Autores principales: | , , , |
| Formato: | equations & formulas research tables/charts Journal Article |
| Publicado: |
Springer Nature
Oct2020
|
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=ccm&AN=146224563&site=ehost-live header: @attributes: shortDbName: ccm uiTerm: 146224563 longDbName: CINAHL Complete uiTag: AN controlInfo: bkinfo: dissinfo: jinfo: jid: 01485598 4N0 jtl: Journal of Medical Systems issn: 01485598 maglogo: N pubinfo: dt: Oct2020 vid: 44 iid: 10 pid: 237 pub: Springer Nature place: New York, New York artinfo: ui: 146224563 146224563 146224563 10.1007/s10916-020-01646-y 146224563 ppct: 1 formats: fmt: – @attributes: type: T – @attributes: type: P tig: atl: A Genetic Attack Against Machine Learning Classifiers to Steal Biometric Actigraphy Profiles from Health Related Sensor Data. aug: au: Garcia-Ceja, Enrique Morin, Brice Aguilar-Rivera, Anton Riegler, Michael Alexander affil: SINTEF Digital, Oslo, Norway sug: subj: Machine Learning Actigraphy Biometrics Signal Processing, Computer Assisted Algorithms Confidence Human Models, Theoretical Computer Simulation ab: In this work, we propose the use of a genetic-algorithm-based attack against machine learning classifiers with the aim of 'stealing' users' biometric actigraphy profiles from health related sensor data. The target classification model uses daily actigraphy patterns for user identification. The biometric profiles are modeled as what we call impersonator examples which are generated based solely on the predictions' confidence score by repeatedly querying the target classifier. We conducted experiments in a black-box setting on a public dataset that contains actigraphy profiles from 55 individuals. The data consists of daily motion patterns recorded with an actigraphy device. These patterns can be used as biometric profiles to identify each individual. Our attack was able to generate examples capable of impersonating a target user with a success rate of 94.5%. Furthermore, we found that the impersonator examples have high transferability to other classifiers trained with the same training set. We also show that the generated biometric profiles have a close resemblance to the ground truth profiles which can lead to sensitive data exposure, like revealing the time of the day an individual wakes-up and goes to bed. pubtype: Academic Journal doctype: equations & formulas research tables/charts Journal Article ougenre: Article language: English refInfo: holdings: @attributes: islocal: N |
|---|