← Latest papers
💻 computer science

Comparative Insights on Adversarial Machine Learning from Industry and Academia: A User-Study Approach

This paper presents a dual study combining an industry survey and student-focused Capture The Flag challenges to demonstrate the link between cybersecurity education and adversarial machine learning awareness, ultimately advocating for the integration of security concepts into machine learning curricula.

Original authors: Vishruti Kakkad (Carnegie Mellon University), Paul Chung (University of California, San Diego), Hanan Hibshi (Carnegie Mellon University, King Abdulaziz University), Maverick Woo (Carnegie Mellon Univ
Published 2026-04-28
📖 5 min read🧠 Deep dive

Original authors: Vishruti Kakkad (Carnegie Mellon University), Paul Chung (University of California, San Diego), Hanan Hibshi (Carnegie Mellon University, King Abdulaziz University), Maverick Woo (Carnegie Mellon University)

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the world of Artificial Intelligence (AI) as a massive, super-smart kitchen where chefs (Machine Learning models) are learning to cook delicious meals by tasting thousands of recipes. Adversarial Machine Learning (AML) is the study of what happens when a saboteur sneaks into that kitchen to mess things up. They might poison the ingredients, trick the chef into tasting the wrong flavors, or steal the secret recipe book.

This paper is like a report from two different groups of people trying to understand how to protect that kitchen: the Professional Chefs (industry experts) and the Culinary Students (academics).

Here is the story of their findings, broken down simply:

Part 1: The Professional Kitchen (Study 1)

The researchers went out and interviewed 12 working experts in cybersecurity and AI. They wanted to know: Do these pros know about the saboteurs, and how do they stay safe?

The Big Discovery:
It turns out, knowing how to cook (Machine Learning) doesn't automatically mean you know how to guard the kitchen (Security).

  • The "Security Education" Effect: The experts who had specific training in security or privacy were the ones who were most worried about the saboteurs.
  • The "Cooking" Blind Spot: Surprisingly, the experts who were great at building AI models but didn't have security training often didn't realize how vulnerable their models were. They were so focused on making the food taste good that they forgot to check if the ingredients were poisoned.

How They Stay Informed:
When asked how they keep up with new threats, the pros didn't say they played games or did puzzles. Instead, they relied on:

  • Social media (like LinkedIn or X/Twitter).
  • News feeds and blogs.
  • Crucially: None of them mentioned using "Capture-the-Flag" (CTF) games to learn. They saw these games as something for students, not serious professionals.

The Hurdles:
The experts said they often don't add extra security layers because:

  1. It might ruin the taste: They worry security checks will make the AI slower or less accurate.
  2. Ethics and Money: They care a lot about doing the "right thing" (ethics) and making sure it's convenient, but money was less of a dealbreaker than they expected.

Part 2: The Student Training Ground (Study 2)

The researchers then decided to test a new idea: What if we taught students about AI security using "Capture-the-Flag" (CTF) games?

Think of a CTF as a video game where you have to solve puzzles to find hidden "flags" (points). The team built two specific games for students:

  • Game 1 (The Beginner): A chatbot that learns as you talk to it. The goal was to trick it into getting really confident about the wrong answers (like a student memorizing the wrong answers for a test).
  • Game 2 (The Advanced): A more complex chatbot where the goal was to "poison" its memory so it would forget how to order a specific cookie (a "poisoning attack").

The Results:

  • The "Aha!" Moment: Before playing, students didn't realize how connected AI and security were. After playing, they started to see the link. They realized, "Oh, if I can trick this game, I can trick a real AI!"
  • The Difficulty: The first game was fun and easy. The second game was tough; nobody managed to "win" it, but they still learned a lot by trying.
  • The Surprise: Even though the students enjoyed the games, the study confirmed that CTFs are currently missing from the professional world. The pros don't use them, and the students are the only ones playing them.

The Final Recipe (Recommendations)

Based on what they learned from both the pros and the students, the authors suggest a new way to cook up safer AI:

  1. Train the Chefs: We need to teach AI engineers about security, not just how to build models. It's like teaching a chef how to spot a rotten egg, not just how to bake a cake.
  2. Play More Games: Since students learn well through CTFs, we should build more of these games for AI security and get professionals to play them too.
  3. Clean the Ingredients: Before training an AI, we must scrub the data (the ingredients) to make sure no "poison" is hiding in there.
  4. Mix the Teams: Security experts and AI engineers need to work together in the same kitchen, not in separate rooms.
  5. Ethics First: We can't just focus on speed; we have to care about the ethics and privacy of the data we use.

In a nutshell: The paper argues that right now, the people building AI often forget to lock the doors, and the people guarding the doors don't always understand how the kitchen works. The solution is to bring them together, teach them both, and use fun, game-like challenges to make learning about security exciting for everyone.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →