Adversarial Reprogramming of Pretrained Neural Networks for Fraud Detection

Adversarial Reprogramming of Pretrained Neural Networks for Fraud Detection
复制标题

用于欺诈检测的预训练神经网络的对抗性重编程

DOI:
10.1145/3459637.3482053
复制
发表时间:
2021
期刊:
International Conference on Information and Knowledge Management (CIKM
影响因子:
--
通讯作者:
Ye, Yanfang
Ye, Yanfang
中科院分区:
--
文献类型:
--
作者:
Chen, Lingwei;Fan, Yujie;Ye, Yanfang

文献摘要

参考文献

被引文献

相似文献

机器学习模型已被广泛用于欺诈检测,而开发和维护这些模型往往受到训练数据稀缺和资源受限的严重限制。为了解决这些问题,在本文中,我们利用机器学习对对抗性攻击的脆弱性,并设计了一种新的模型AdvRFD,该模型对ImageNet分类神经网络进行对抗性重新编程,用于欺诈检测任务。AdvRFD首先将交易特征嵌入到宿主图像中以构建新的ImageNet数据,然后学习要添加到所有输入的通用扰动,以便预训练模型的输出可以相应地映射到所有交易的最终检测决策。在以太坊和信用卡上进行的两个交易数据集上的广泛实验表明,AdvRFD可以有效地使用有限的数据和资源来检测欺诈。
Machine learning models have been widely used for fraud detection, while developing and maintaining these models often suffers from significant limitations in terms of training data scarcity and constrained resources. To address these issues, in this paper, we leverage machine learning vulnerability to adversarial attacks, and design a novel model AdvRFD that Adversarially Reprograms an ImageNet classification neural network for Fraud Detection task. AdvRFD first embeds transaction features into a host image to construct new ImageNet data, and then learns a universal perturbation to be added to all inputs, such that the outputs of the pretrained model can be accordingly mapped to the final detection decisions for all transactions. Extensive experiments on two transaction datasets made over Ethereum and credit cards have demonstrated that AdvRFD is effective to detect fraud using limited data and resources.
DOI: 10.1145/3397271.3401253
发表时间: 2020-05
期刊: Proceedings of the 43rd International ACM SIGIR Conference on Research and Development in Information Retrieval
影响因子: --
作者:
Zhiwei Liu;Yingtong Dou;Philip S. Yu;Yutong Deng;Hao Peng-
通讯作者: Zhiwei Liu;Yingtong Dou;Philip S. Yu;Yutong Deng;Hao Peng-
将攻击转化为保护:使用对抗性攻击的社交媒体隐私保护
DOI: --
发表时间: 2021
期刊: SDM
影响因子: --
作者:
Xiaoting Li;Lingwei Chen;Dinghao Wu
通讯作者: Dinghao Wu