Historical milestone · 2006
Can machine learning be secure?
Reviewed through September 18, 2026
2006 · Historical milestone
Can machine learning be secure?
- Era
- 2000s
- Theme
- Safety, security & alignment
- Evidence form
- Taxonomy organized attacks by influence, security violation, and specificity and analyzed spam, intrusion, and other learning systems
- School / paradigm
- Adversarial machine learning / security
- Institution / context
- UC Berkeley
- Researchers
- Marco Barreno; Blaine Nelson; Russell Sears; Anthony Joseph; J. D. Tygar
School of thought
Safety, security, and machine ethics
Matched on representative researcher.
Intelligent systems must be treated as potentially fallible or adversarial components embedded in technical and social control structures.
Critique. Hard guarantees rarely cover adaptive learned systems and open environments; governance can lag capability.
Modern descendants. Alignment, prompt-injection defense, agent permissions, red teaming, incident response, and AI assurance.
Understand
Plain-language record, transferred from the reviewed source module.
Theory or experimental setup. Connected ML failures to explicit attacker goals and security threat modeling.
Result / historical claim. Early case studies preceded modern deep models, foundation-model interfaces, and tool-using agents.
Apply
Professional implication, only where the reviewed record states one.
The checked-in record does not state a separate professional application for this entry. The topic page places it in the wider research lineage: Safety, security, and alignment.
Verify
Evidence status, stated limitations, and the external sources this record actually carries.
Evidence form. Taxonomy organized attacks by influence, security violation, and specificity and analyzed spam, intrusion, and other learning systems
Limitation / debate. Threat models, poisoning/evasion taxonomies, security evaluation, and adversarial ML programs.
Source status. The source link below is the verified link our reviewed topic research already carries for this milestone.
Reproduce
A reproduction tutorial is linked only when one exists for this exact record.
A reproduction tutorial is not yet available for this entry. The closest reviewed material is Safety, security, and alignment.
Cite or share
APA-like: This historical record carries a year only, and no author or publisher of record in the checked-in data. An APA reference would have to invent that metadata.
BibTeX: BibTeX requires an author and publication venue. Historical lineage entries store a narrative record and its source link, not structured authorship, so the field would be fabricated.
