A machine-learning component can become a weak point in a larger security system even when other components continue to work as designed. This paper studies that risk in Gmail, where Magika identifies attachment types and routes files to specialized malware detectors.
Adversarial changes to the file-type model can send a malicious attachment to an unsuitable scanner. The paper evaluates this system-level failure mode, develops a defense and measures its effect on attack success. The resulting mitigation was deployed in Gmail.
See also Magika, the file-type detection model examined in this study.