Adversarial Threats Across the ML Lifecycle: A Red Team Perspective | Sanket Badhe, TikTok

Adversarial Threats Across the ML Lifecycle: A Red Team Perspective | Sanket Badhe, TikTok

🎙 Sanket Badhe 👥 5K 📅 October 20, 2025 ⏱ 35 min 👁 42 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

adversarial attacksML lifecycledata poisoningmodel extractionprompt injectionfeedback loopsred teaming

Summary

In this talk from MLOps World 2025, Sanket Badhe, a Senior ML Engineer at TikTok, provides a red team perspective on adversarial threats across the entire machine learning lifecycle. He emphasizes that ML systems are vulnerable at every stage, from data collection to deployment and feedback loops. The talk is structured around four main attack categories: evasion, poisoning, extraction, and inference. Badhe details specific attack vectors, including data poisoning and backdoor attacks (e.g., BadNets), evasion attacks using adversarial examples (e.g., Goodfellow’s panda), model extraction via API queries, and prompt injection in LLMs. He also discusses feedback loop manipulation, citing the Microsoft Tay incident as a cautionary tale. The speaker proposes defense strategies such as data lineage tracking, adversarial training, input validation, and monitoring. He highlights the importance of red teaming with specialized tools like IBM’s ART, TextAttack, and MITRE ATLAS. The talk concludes by stressing that ML security is a team sport requiring collaboration between ML engineers, security teams, and MLOps, and that security must be proactive and continuous.

169 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides a comprehensive and structured overview of adversarial threats across the ML lifecycle, making it valuable for practitioners seeking to understand the attack surface. The argumentation is solid, supported by well-known examples such as BadNets, Goodfellow’s adversarial examples, and Microsoft Tay. The speaker logically progresses from threat modeling to specific attack phases, then to defense strategies and organizational considerations. However, the talk is primarily an expert opinion rather than a rigorous scientific review; it lacks detailed citations and empirical evidence for some claims. The practical insights and actionable recommendations enhance its value, but the depth of technical detail is moderate, suitable for a broad audience rather than deep technical specialists.

Scientific Rigor, Source Quality, Title Accuracy

The talk demonstrates a good understanding of the subject, but the scientific rigor is limited by the absence of formal references. The speaker mentions research papers (e.g., BadNets) and tools (e.g., IBM ART, TextAttack, MITRE ATLAS) but does not provide specific citations or URLs. The description includes only a link to the MLOps World website, which is not a direct source for the claims. The title accurately reflects the content, and the talk is well-structured. The lack of verifiable sources reduces the overall scientific credibility, but the content aligns with established knowledge in the field. The speaker’s industry experience adds practical credibility, but for a rigorous scientific evaluation, more explicit sourcing would be expected.

241 words

Title / Content Match

The title accurately reflects the content: a red team perspective on adversarial threats across the ML lifecycle.

Quality & Reliability

7/10

The talk is an expert opinion by a senior ML engineer from TikTok, providing a structured overview of adversarial ML threats. It references real-world examples and research (e.g., BadNets, Goodfellow's adversarial examples, Microsoft Tay) but lacks detailed citations or verification of claims. The content is practical and aligns with industry knowledge, but the absence of formal references and the reliance on anecdotal evidence slightly reduce its scientific rigor.

Key Moments

Cited Sources

  • MLOps World — Conference website where the talk was presented.

Concurring Sources

Contribution & Novelties

The talk provides a practical, industry-oriented overview of adversarial threats across the ML lifecycle, emphasizing the need for a holistic security approach. It synthesizes known attack vectors and defense strategies into a structured framework, making it accessible to practitioners. The emphasis on feedback loops and organizational collaboration adds a unique perspective.

Pour aller plus loin :

110 words

Radar Profile

The radar profile shows a balanced but moderate performance across all dimensions, with slightly higher scores in information quantity and quality, reflecting the talk's comprehensive coverage. The lower technical depth and reliability scores indicate that while the content is informative, it lacks rigorous scientific depth and formal citations.

Reliability 6/10

💬 Sur les 0 commentaires analysés, aucune tendance n'est disponible.