Historical milestone · 2006

    Can machine learning be secure?

    Reviewed through September 18, 2026

    2006 · Historical milestone

    Can machine learning be secure?

    Era
    2000s
    Theme
    Safety, security & alignment
    Evidence form
    Taxonomy organized attacks by influence, security violation, and specificity and analyzed spam, intrusion, and other learning systems
    School / paradigm
    Adversarial machine learning / security
    Institution / context
    UC Berkeley
    Researchers
    Marco Barreno; Blaine Nelson; Russell Sears; Anthony Joseph; J. D. Tygar

    School of thought

    Safety, security, and machine ethics

    Matched on representative researcher.

    Intelligent systems must be treated as potentially fallible or adversarial components embedded in technical and social control structures.

    Critique. Hard guarantees rarely cover adaptive learned systems and open environments; governance can lag capability.

    Modern descendants. Alignment, prompt-injection defense, agent permissions, red teaming, incident response, and AI assurance.

    Understand

    Plain-language record, transferred from the reviewed source module.

    Theory or experimental setup. Connected ML failures to explicit attacker goals and security threat modeling.

    Result / historical claim. Early case studies preceded modern deep models, foundation-model interfaces, and tool-using agents.

    Apply

    Professional implication, only where the reviewed record states one.

    The checked-in record does not state a separate professional application for this entry. The topic page places it in the wider research lineage: Safety, security, and alignment.

    Verify

    Evidence status, stated limitations, and the external sources this record actually carries.

    Evidence form. Taxonomy organized attacks by influence, security violation, and specificity and analyzed spam, intrusion, and other learning systems

    Limitation / debate. Threat models, poisoning/evasion taxonomies, security evaluation, and adversarial ML programs.

    Source status. The source link below is the verified link our reviewed topic research already carries for this milestone.

    Reproduce

    A reproduction tutorial is linked only when one exists for this exact record.

    A reproduction tutorial is not yet available for this entry. The closest reviewed material is Safety, security, and alignment.

    Cite or share

    APA-like: This historical record carries a year only, and no author or publisher of record in the checked-in data. An APA reference would have to invent that metadata.

    BibTeX: BibTeX requires an author and publication venue. Historical lineage entries store a narrative record and its source link, not structured authorship, so the field would be fabricated.

    Related