Ad-versarial: Defeating Perceptual Ad-Blocking
Perceptual ad-blocking is a novel approach that uses visual cues to detect online advertisements. Compared to classical filter lists, perceptual ad-blocking is believed to be less prone to an arms race with web publishers and ad-networks. In this work we use techniques from adversarial machine learning to demonstrate that this may not be the case. We show that perceptual ad-blocking engenders a new arms race that likely disfavors ad-blockers. Unexpectedly, perceptual ad-blocking can also introduce new vulnerabilities that let an attacker bypass web security boundaries and mount DDoS attacks. We first analyze the design space of perceptual ad-blockers and present a unified architecture that incorporates prior academic and commercial work. We then explore a variety of attacks on the ad-blocker's full visual-detection pipeline, that enable publishers or ad-networks to evade or detect ad-blocking, and at times even abuse its high privilege level to bypass web security boundaries. Our attacks exploit the unreasonably strong threat model that perceptual ad-blockers must survive. Finally, we evaluate a concrete set of attacks on an ad-blocker's internal ad-classifier by instantiating adversarial examples for visual systems in a real web-security context. For six ad-detection techniques, we create perturbed ads, ad-disclosures, and native web content that misleads perceptual ad-blocking with 100% success rates. For example, we demonstrate how a malicious user can upload adversarial content (e.g., a perturbed image in a Facebook post) that fools the ad-blocker into removing other users' non-ad content.
Authors

Are you an author of this paper? Check the Twitter handle we have for you is correct.

Florian Tramèr (add twitter)
Pascal Dupré (add twitter)
Gili Rusak (add twitter)
Giancarlo Pellegrino (edit)
Dan Boneh (edit)
Ask The Authors

Ask the authors of this paper a question or leave a comment.

Read it. Rate it.
#1. Which part of the paper did you read?

#2. The paper contains new data or analyses that is openly accessible?
#3. The conclusion is supported by the data and analyses?
#4. The conclusion is of scientific interest?
#5. The result is likely to lead to future research?

Github
User:
Stargazers:
1
Forks:
0
Open Issues:
1
Network:
0
Subscribers:
2
Language:
Python
Youtube
Link:
None (add)
Views:
0
Likes:
0
Dislikes:
0
Favorites:
0
Comments:
0
Other
Sample Sizes (N=):
Inserted:
Words Total:
Words Unique:
Source:
Abstract:
None
11/08/18 06:05PM
16,681
4,446
Tweets
larsr: https://t.co/DTAqWHxhjp
GSSGhana: RT @x0rz: Ad-versarial: Defeating Perceptual Ad-Blocking https://t.co/Jg49Eq7y1a (PDF) #adblocking #machinelearning https://t.co/kgiaLPaZ5A
tgianko: @dakami Not sure if that'd work. The defender doesn't know pixels being perturbed. Perturbation can involve more pixels, possibly all. We showed an attack where the publisher can apply a sheet of perturbations over the entire webpage. Here the link to the paper https://t.co/xxoTvkpFUw
AlesiaChernikov: RT @NicolasPapernot: Ad-versarial examples for perceptual adblocking by Tramer et al. https://t.co/4bM49UIar4 https://t.co/uKCoQubTyX
0_vortex: RT @x0rz: Ad-versarial: Defeating Perceptual Ad-Blocking https://t.co/Jg49Eq7y1a (PDF) #adblocking #machinelearning https://t.co/kgiaLPaZ5A
PaulRLacey: Ad-versarial: Defeating Perceptual Ad-Blocking (pdf) | Arxiv https://t.co/RvL9ie7XqG
coolrob: RT @x0rz: Ad-versarial: Defeating Perceptual Ad-Blocking https://t.co/Jg49Eq7y1a (PDF) #adblocking #machinelearning https://t.co/kgiaLPaZ5A
Memoirs: Ad-versarial: Defeating Perceptual Ad-Blocking. https://t.co/TENjYBOXt0
shubh_300595: RT @arxiv_org: Ad-versarial: Defeating Perceptual Ad-Blocking. https://t.co/FobqD3DFDB https://t.co/Z6gon24IUo
Gabito73953724: RT @x0rz: Ad-versarial: Defeating Perceptual Ad-Blocking https://t.co/Jg49Eq7y1a (PDF) #adblocking #machinelearning https://t.co/kgiaLPaZ5A
Zahid_Akhtar: RT @NicolasPapernot: Ad-versarial examples for perceptual adblocking by Tramer et al. https://t.co/4bM49UIar4 https://t.co/uKCoQubTyX
Nikhil_Rathor: RT @x0rz: Ad-versarial: Defeating Perceptual Ad-Blocking https://t.co/Jg49Eq7y1a (PDF) #adblocking #machinelearning https://t.co/kgiaLPaZ5A
arxiv_org: Ad-versarial: Defeating Perceptual Ad-Blocking. https://t.co/FobqD3DFDB https://t.co/Z6gon24IUo
tgianko: Perceptual adblockers are great but operate in the worst threat model possible for computer vision/ML with attacks going beyond mere evasion/detection. We present all that and much more in a new paper with F. Tramèr, P. Dupré, G. Rusak and D. Boneh https://t.co/xb5GG6u7nt https://t.co/iu4FLyzVD5
BitAengel: RT @x0rz: Ad-versarial: Defeating Perceptual Ad-Blocking https://t.co/Jg49Eq7y1a (PDF) #adblocking #machinelearning https://t.co/kgiaLPaZ5A
machinelearn_d: RT @x0rz: Ad-versarial: Defeating Perceptual Ad-Blocking https://t.co/Jg49Eq7y1a (PDF) #adblocking #machinelearning https://t.co/kgiaLPaZ5A
kapitaali_com: RT @x0rz: Ad-versarial: Defeating Perceptual Ad-Blocking https://t.co/Jg49Eq7y1a (PDF) #adblocking #machinelearning https://t.co/kgiaLPaZ5A
AI_Syndicate: RT @x0rz: Ad-versarial: Defeating Perceptual Ad-Blocking https://t.co/Jg49Eq7y1a (PDF) #adblocking #machinelearning https://t.co/kgiaLPaZ5A
harryrubicon: RT @x0rz: Ad-versarial: Defeating Perceptual Ad-Blocking https://t.co/Jg49Eq7y1a (PDF) #adblocking #machinelearning https://t.co/kgiaLPaZ5A
shouso: RT @x0rz: Ad-versarial: Defeating Perceptual Ad-Blocking https://t.co/Jg49Eq7y1a (PDF) #adblocking #machinelearning https://t.co/kgiaLPaZ5A
peterhil: RT @x0rz: Ad-versarial: Defeating Perceptual Ad-Blocking https://t.co/Jg49Eq7y1a (PDF) #adblocking #machinelearning https://t.co/kgiaLPaZ5A
meninapi: RT @x0rz: Ad-versarial: Defeating Perceptual Ad-Blocking https://t.co/Jg49Eq7y1a (PDF) #adblocking #machinelearning https://t.co/kgiaLPaZ5A
duzkaramsar: RT @x0rz: Ad-versarial: Defeating Perceptual Ad-Blocking https://t.co/Jg49Eq7y1a (PDF) #adblocking #machinelearning https://t.co/kgiaLPaZ5A
x0rz: Ad-versarial: Defeating Perceptual Ad-Blocking https://t.co/Jg49Eq7y1a (PDF) #adblocking #machinelearning https://t.co/kgiaLPaZ5A
nmfeeds: [O] https://t.co/hqtSh3TgTe Ad-versarial: Defeating Perceptual Ad-Blocking. Perceptual ad-blocking is a novel approach tha...
arxivml: "Ad-versarial: Defeating Perceptual Ad-Blocking", Florian Tramèr, Pascal Dupré, Gili Rusak, Giancarlo Pellegrino, D… https://t.co/nt73UM8cE2
cynicalsecurity: F. Tramèr et al., “Ad-versarial: Defeating Perceptual Ad-Blocking” https://t.co/0qpdmzJw3j
surangasms01: RT @NicolasPapernot: Ad-versarial examples for perceptual adblocking by Tramer et al. https://t.co/4bM49UIar4 https://t.co/uKCoQubTyX
ak1010: Ad-versarial: Defeating Perceptual Ad-Blocking - https://t.co/4H7G24DgYh
savanvisalpara7: RT @NicolasPapernot: Ad-versarial examples for perceptual adblocking by Tramer et al. https://t.co/4bM49UIar4 https://t.co/uKCoQubTyX
kamilsindi: RT @NicolasPapernot: Ad-versarial examples for perceptual adblocking by Tramer et al. https://t.co/4bM49UIar4 https://t.co/uKCoQubTyX
NicolasPapernot: Ad-versarial examples for perceptual adblocking by Tramer et al. https://t.co/4bM49UIar4 https://t.co/uKCoQubTyX
Images
Related