{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,29]],"date-time":"2025-08-29T10:33:13Z","timestamp":1756463593310,"version":"3.41.0"},"reference-count":82,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2023,4,12]],"date-time":"2023-04-12T00:00:00Z","timestamp":1681257600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Science Foundation (NSF) Award","award":["#2247141 and #2209636"],"award-info":[{"award-number":["#2247141 and #2209636"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2023,5,31]]},"abstract":"<jats:p>\n            Adversarial attacks against supervised learning\n            <jats:bold>a<\/jats:bold>\n            algorithms, which necessitates the application of logging while using supervised learning algorithms in software projects. Logging enables practitioners to conduct postmortem analysis, which can be helpful to diagnose any conducted attacks. We conduct an empirical study to identify and characterize log-related coding patterns, i.e., recurring coding patterns that can be leveraged to conduct adversarial attacks and needs to be logged. A list of log-related coding patterns can guide practitioners on what to log while using supervised learning algorithms in software projects.\n          <\/jats:p>\n          <jats:p>\n            We apply qualitative analysis on 3,004 Python files used to implement 103 supervised learning-based software projects. We identify a list of 54 log-related coding patterns that map to six attacks related to supervised learning algorithms. Using\n            <jats:italic>\n              <jats:bold>Lo<\/jats:bold>\n              g Assistant to conduct\n              <jats:bold>P<\/jats:bold>\n              ostmortems for\n              <jats:bold>Su<\/jats:bold>\n              pervised\n              <jats:bold>L<\/jats:bold>\n              earning (\n              <jats:bold>LOPSUL<\/jats:bold>\n              )\n            <\/jats:italic>\n            , we quantify the frequency of the identified log-related coding patterns with 278 open-source software projects that use supervised learning. We observe log-related coding patterns to appear for 22% of the analyzed files, where training data forensics is the most frequently occurring category.\n          <\/jats:p>","DOI":"10.1145\/3568020","type":"journal-article","created":{"date-parts":[[2022,12,14]],"date-time":"2022-12-14T12:16:16Z","timestamp":1671020176000},"page":"1-24","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Log-related Coding Patterns to Conduct Postmortems of Attacks in Supervised Learning-based Projects"],"prefix":"10.1145","volume":"26","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0261-2196","authenticated-orcid":false,"given":"Farzana Ahamed","family":"Bhuiyan","sequence":"first","affiliation":[{"name":"Meta, Seattle, Washington"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5056-757X","authenticated-orcid":false,"given":"Akond","family":"Rahman","sequence":"additional","affiliation":[{"name":"Auburn University, Auburn, Alabama"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,4,12]]},"reference":[{"key":"e_1_3_1_2_2","unstructured":"ast \u2014 Abstract Syntax Trees. (n.d.). Retrieved from https:\/\/docs.python.org\/3\/library\/ast.html."},{"key":"e_1_3_1_3_2","unstructured":"Model Zoo: Discover open source deep learning code and pretrained models. (n.d.). Retrieved from https:\/\/modelzoo.co."},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/3183519.3183549"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.2139\/ssrn.3547322"},{"key":"e_1_3_1_6_2","article-title":"Verifiability Package for Paper","author":"Authors Anonymous","year":"2020","unstructured":"Anonymous Authors. 2020. Verifiability Package for Paper. Retrieved February 10, 2021 from https:\/\/figshare.com\/s\/689c268c1de59dc7c2bf.","journal-title":"Retrieved February 10, 2021 from https:\/\/figshare.com\/s\/689c268c1de59dc7c2bf."},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/2889160.2889231"},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-010-5188-5"},{"key":"e_1_3_1_9_2","unstructured":"Farzana Ahamed Bhuyian and Akond Rahman. 2022. Source Code of LOPSUL. (2022). Retrieved from https:\/\/github.com\/paser-group\/MLForensics."},{"key":"e_1_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00009"},{"key":"e_1_3_1_11_2","unstructured":"Bryant Chen Wilka Carvalho Nathalie Baracaldo Heiko Ludwig Benjamin Edwards Taesung Lee Ian Molloy and Biplav Srivastava. 2018. Detecting backdoor attacks on deep neural networks by activation clustering. arXiv:1811.03728. Retrieved from https:\/\/arxiv.org\/abs\/1811.03728."},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2017.15"},{"key":"e_1_3_1_13_2","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380408"},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-019-09690-0"},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1177\/001316446002000104"},{"key":"e_1_3_1_16_2","volume-title":"Doing Qualitative Research","author":"Crabtree Benjamin F.","year":"1999","unstructured":"Benjamin F. Crabtree and William L. Miller. 1999. Doing Qualitative Research. Sage Publications."},{"key":"e_1_3_1_17_2","first-page":"139","volume-title":"Proceedings of the 2015 Annual Technical Conference","author":"Ding Rui","year":"2015","unstructured":"Rui Ding, Hucheng Zhou, Jian-Guang Lou, Hongyu Zhang, Qingwei Lin, Qiang Fu, Dongmei Zhang, and Tao Xie. 2015. Log2: A cost-aware logging mechanism for performance diagnosis. In Proceedings of the 2015 Annual Technical Conference. 139\u2013150."},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P18-2006"},{"issue":"3","key":"e_1_3_1_19_2","first-page":"4","article-title":"Robust physical-world attacks on machine learning models","volume":"2","author":"Evtimov Ivan","year":"2017","unstructured":"Ivan Evtimov, Kevin Eykholt, Earlence Fernandes, Tadayoshi Kohno, Bo Li, Atul Prakash, Amir Rahmati, and Dawn Song. 2017. Robust physical-world attacks on machine learning models. arXiv preprint arXiv:1707.08945 2, 3 (2017), 4.","journal-title":"arXiv preprint arXiv:1707.08945"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.1126\/science.aaw4399"},{"key":"e_1_3_1_22_2","first-page":"17","volume-title":"Proceedings of the 23rd {USENIX} Security Symposium","author":"Fredrikson Matthew","year":"2014","unstructured":"Matthew Fredrikson, Eric Lantz, Somesh Jha, Simon Lin, David Page, and Thomas Ristenpart. 2014. Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing. In Proceedings of the 23rd {USENIX} Security Symposium. 17\u201332."},{"key":"e_1_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/2591062.2591175"},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/2591062.2591175"},{"key":"e_1_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/3125780"},{"key":"e_1_3_1_26_2","first-page":"72","volume-title":"Proceedings of the Summer School on Machine Learning","author":"Ghahramani Zoubin","year":"2003","unstructured":"Zoubin Ghahramani. 2003. Unsupervised learning. In Proceedings of the Summer School on Machine Learning. Springer, 72\u2013112."},{"key":"e_1_3_1_27_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Goodfellow Ian","year":"2015","unstructured":"Ian Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and harnessing adversarial examples. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_28_2","unstructured":"Robert David Hart. When artificial intelligence botches your medical diagnosis who\u2019s to blame? (n.d.). Retrieved from https:\/\/qz.com\/989137\/when-a-robot-ai-doctor-misdiagnoses-you-whos-to-blame\/"},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238193"},{"key":"e_1_3_1_30_2","article-title":"Towards security threats of deep learning systems: A survey","author":"He Yingzhe","year":"2020","unstructured":"Yingzhe He, Guozhu Meng, Kai Chen, Xingbo Hu, and Jinwen He. 2020. Towards security threats of deep learning systems: A survey. IEEE Transactions on Software Engineering (2020).","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_3_1_31_2","article-title":"Towards security threats of deep learning systems: A survey","author":"He Yingzhe","year":"2020","unstructured":"Yingzhe He, Guozhu Meng, Kai Chen, Xingbo Hu, and Jinwen He. 2020. Towards security threats of deep learning systems: A survey. IEEE Transactions on Software Engineering (2020).","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/2046684.2046692"},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1126\/science.aaa8415"},{"key":"e_1_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.5555\/1622737.1622748"},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/2746194.2746200"},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-016-9449-1"},{"key":"e_1_3_1_37_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Krishna Kalpesh","year":"2020","unstructured":"Kalpesh Krishna, Gaurav Singh Tomar, Ankur P. Parikh, Nicolas Papernot, and Mohit Iyyer. 2020. Thieves on sesame street! model extraction of BERT-based APIs. In Proceedings of the International Conference on Learning Representations. Retrieved from https:\/\/openreview.net\/forum?id=Byl5NREFDr."},{"key":"e_1_3_1_38_2","unstructured":"Alexey Kurakin Ian Goodfellow Samy Bengio et\u00a0al. 2016. Adversarial examples in the physical world. (2016)."},{"key":"e_1_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.249"},{"key":"e_1_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.2307\/2529310"},{"key":"e_1_3_1_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2020.2970422"},{"key":"e_1_3_1_42_2","article-title":"A qualitative study of the benefits and costs of logging from developers\u2019 perspectives","author":"Li Heng","year":"2020","unstructured":"Heng Li, Weiyi Shang, Bram Adams, Mohammed Sayagh, and Ahmed E. Hassan. 2020. A qualitative study of the benefits and costs of logging from developers\u2019 perspectives. IEEE Transactions on Software Engineering (2020).","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-016-9456-2"},{"key":"e_1_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3416636"},{"key":"e_1_3_1_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSMCC.2011.2170420"},{"key":"e_1_3_1_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2805680"},{"key":"e_1_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2941943"},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2016.51"},{"key":"e_1_3_1_49_2","doi-asserted-by":"publisher","DOI":"10.1109\/JBHI.2014.2344095"},{"key":"e_1_3_1_50_2","article-title":"Tutorial Session: Common Pitfalls for Studying the Human Side of Machine Learning","author":"Mulligan Deirdre","year":"2018","unstructured":"Deirdre Mulligan, Nitin Kohli, and Joshua Kroll. 2018. Tutorial Session: Common Pitfalls for Studying the Human Side of Machine Learning. Retrieved February 22, 2021 from https:\/\/www.facebook.com\/nipsfoundation\/videos\/2003393576419036\/.","journal-title":"https:\/\/www.facebook.com\/nipsfoundation\/videos\/2003393576419036\/."},{"key":"e_1_3_1_51_2","article-title":"A Taxonomy and Terminology of Adversarial Machine Learning","year":"2019","unstructured":"NIST. 2019. A Taxonomy and Terminology of Adversarial Machine Learning. Retrieved February 12, 2021 from https:\/\/csrc.nist.gov\/publications\/detail\/nistir\/8269\/draft.","journal-title":"Retrieved February 12, 2021 from https:\/\/csrc.nist.gov\/publications\/detail\/nistir\/8269\/draft."},{"key":"e_1_3_1_52_2","doi-asserted-by":"publisher","DOI":"10.1145\/2076450.2076466"},{"key":"e_1_3_1_53_2","doi-asserted-by":"publisher","DOI":"10.1145\/3270101.3270102"},{"key":"e_1_3_1_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00035"},{"key":"e_1_3_1_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/RBME.2020.3013489"},{"key":"e_1_3_1_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2020.2975048"},{"key":"e_1_3_1_57_2","article-title":"NeurIPS 2018: Rethinking transparency and accountability in machine learning","author":"R. Bhagasree","year":"2018","unstructured":"Bhagasree R.2018. NeurIPS 2018: Rethinking transparency and accountability in machine learning. Retrieved February 23, 2021 from https:\/\/hub.packtpub.com\/neurips-2018-rethinking-transparency-and-accountability-in-machine-learning\/.","journal-title":"https:\/\/hub.packtpub.com\/neurips-2018-rethinking-transparency-and-accountability-in-machine-learning\/."},{"key":"e_1_3_1_58_2","doi-asserted-by":"publisher","DOI":"10.1145\/3408897"},{"key":"e_1_3_1_59_2","doi-asserted-by":"publisher","DOI":"10.1109\/REW.2019.00033"},{"issue":"3","key":"e_1_3_1_60_2","first-page":"4","article-title":"AI a modern approach","volume":"2","author":"Russell Stuart","year":"2005","unstructured":"Stuart Russell and Peter Norvig. 2005. AI a modern approach. Learning 2, 3 (2005), 4.","journal-title":"Learning"},{"key":"e_1_3_1_61_2","unstructured":"Ahmed Salem Rui Wen Michael Backes Shiqing Ma and Yang Zhang. 2020. Dynamic backdoor attacks against machine learning models. arXiv:2003.03675. Retrieved from https:\/\/arxiv.org\/abs\/2003.03675."},{"key":"e_1_3_1_62_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2014.09.003"},{"key":"e_1_3_1_63_2","doi-asserted-by":"publisher","DOI":"10.1109\/MDAT.2020.2971217"},{"key":"e_1_3_1_64_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"e_1_3_1_65_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00028"},{"key":"e_1_3_1_66_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134077"},{"key":"e_1_3_1_67_2","article-title":"Certified defenses for data poisoning attacks","author":"Steinhardt Jacob","year":"2017","unstructured":"Jacob Steinhardt, Pang Wei Koh, and Percy Liang. 2017. Certified defenses for data poisoning attacks. In Proceedings of the NIPS\u201917 31st International Conference on Neural Information Processing Systems.","journal-title":"Proceedings of the NIPS\u201917 31st International Conference on Neural Information Processing Systems."},{"key":"e_1_3_1_68_2","volume-title":"Reinforcement Learning: An Introduction","author":"Sutton Richard S.","year":"2018","unstructured":"Richard S. Sutton and Andrew G. Barto. 2018. Reinforcement Learning: An Introduction. MIT Press."},{"key":"e_1_3_1_69_2","article-title":"A taxonomy and terminology of adversarial machine learning","author":"Tabassi Elham","year":"2019","unstructured":"Elham Tabassi, Kevin Burns, Michael Hadjimichael, Andres Molina-Markham, and Julian Sexton. 2019. A taxonomy and terminology of adversarial machine learning. NIST IR (2019).","journal-title":"NIST IR"},{"key":"e_1_3_1_70_2","volume-title":"Introduction to Data Mining (1st. ed.)","author":"Tan Pang-Ning","year":"2005","unstructured":"Pang-Ning Tan, Michael Steinbach, and Vipin Kumar. 2005. Introduction to Data Mining (1st. ed.). Addison-Wesley Longman Publishing Co., Inc."},{"key":"e_1_3_1_71_2","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"e_1_3_1_72_2","doi-asserted-by":"publisher","DOI":"10.2200\/S00861ED1V01Y201806AIM039"},{"key":"e_1_3_1_73_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00038"},{"key":"e_1_3_1_74_2","article-title":"Backdoor attacks against transfer learning with pre-trained deep learning models","author":"Wang Shuo","year":"2020","unstructured":"Shuo Wang, Surya Nepal, Carsten Rudolph, Marthie Grobler, Shangyu Chen, and Tianle Chen. 2020. Backdoor attacks against transfer learning with pre-trained deep learning models. IEEE Transactions on Services Computing (2020).","journal-title":"IEEE Transactions on Services Computing"},{"key":"e_1_3_1_75_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00027"},{"key":"e_1_3_1_76_2","first-page":"293","volume-title":"Proceedings of the 10th USENIX Conference on Operating Systems Design and Implementation.","author":"Yuan Ding","year":"2012","unstructured":"Ding Yuan, Soyeon Park, Peng Huang, Yang Liu, Michael M. Lee, Xiaoming Tang, Yuanyuan Zhou, and Stefan Savage. 2012. Be conservative: Enhancing failure diagnosis with proactive logging. In Proceedings of the 10th USENIX Conference on Operating Systems Design and Implementation.USENIX Association, 293\u2013306."},{"key":"e_1_3_1_77_2","first-page":"293","volume-title":"Proceedings of the 10th {USENIX} Symposium on Operating Systems Design and Implementation","author":"Yuan Ding","year":"2012","unstructured":"Ding Yuan, Soyeon Park, Peng Huang, Yang Liu, Michael M. Lee, Xiaoming Tang, Yuanyuan Zhou, and Stefan Savage. 2012. Be conservative: Enhancing failure diagnosis with proactive logging. In Proceedings of the 10th {USENIX} Symposium on Operating Systems Design and Implementation. 293\u2013306."},{"key":"e_1_3_1_78_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2012.6227202"},{"key":"e_1_3_1_79_2","doi-asserted-by":"publisher","DOI":"10.1145\/2110356.2110360"},{"key":"e_1_3_1_80_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-019-09687-9"},{"key":"e_1_3_1_81_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2017\/551"},{"key":"e_1_3_1_82_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME.2019.00079"},{"key":"e_1_3_1_83_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2015.60"}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3568020","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3568020","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T21:26:14Z","timestamp":1750281974000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3568020"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,12]]},"references-count":82,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2023,5,31]]}},"alternative-id":["10.1145\/3568020"],"URL":"https:\/\/doi.org\/10.1145\/3568020","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"type":"print","value":"2471-2566"},{"type":"electronic","value":"2471-2574"}],"subject":[],"published":{"date-parts":[[2023,4,12]]},"assertion":[{"value":"2021-08-26","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-09-12","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-04-12","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}