Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning Attacks

Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning Attacks
复制标题

DOI:
--
复制
发表时间:
2020-06
期刊:
ArXiv
影响因子:
--
通讯作者:
Avi Schwarzschild;Micah Goldblum;Arjun Gupta;John P. Dickerson;T. Goldstein
Avi Schwarzschild;Micah Goldblum;Arjun Gupta;John P. Dickerson;T. Goldstein
中科院分区:
其他
文献类型:
--
作者:
Avi Schwarzschild;Micah Goldblum;Arjun Gupta;John P. Dickerson;T. Goldstein

文献摘要

被引文献

相似文献

数据中毒和后门攻击操纵训练数据,以导致模型在推理过程中失败。最近对行业从业者的一项调查发现,数据中毒是从模型窃取到对抗性攻击等威胁中的头号问题。然而,我们发现,令人印象深刻的性能评估数据中毒攻击,在很大程度上,不一致的实验设计的文物。此外,我们发现,现有的中毒方法已经过测试,在人为的情况下,他们在现实的设置失败。为了促进公平比较,在未来的工作中,我们开发了统一的基准数据中毒和后门攻击。
Data poisoning and backdoor attacks manipulate training data in order to cause models to fail during inference. A recent survey of industry practitioners found that data poisoning is the number one concern among threats ranging from model stealing to adversarial attacks. However, we find that the impressive performance evaluations from data poisoning attacks are, in large part, artifacts of inconsistent experimental design. Moreover, we find that existing poisoning methods have been tested in contrived scenarios, and they fail in realistic settings. In order to promote fair comparison in future work, we develop unified benchmarks for data poisoning and backdoor attacks.