Data Poisoning Attacks against MRMR

Data Poisoning Attacks against MRMR
复制标题

针对 MRMR 的数据中毒攻击

DOI:
--
复制
发表时间:
2019
期刊:
IEEE International Conference on Acoustics, Speech, and Signal Processing
影响因子:
--
通讯作者:
G. Ditzler
G. Ditzler
中科院分区:
--
文献类型:
--
作者:
Heng Liu;G. Ditzler

文献摘要

被引文献

相似文献

许多机器学习模型没有考虑到对手可以在训练或测试时更改数据。在过去的十年中,机器学习模型的漏洞一直受到关注,需要更安全的算法。不幸的是,特征选择(FS)的安全性仍然是一个尚未充分探索的领域。解决针对嵌入式 FS 的数据中毒算法的工作很少;然而,针对信息论FS的数据中毒技术并不存在。在这篇文章中,提出了一种新颖的数据中毒算法,其目标是最小冗余最大相关性(mRMR)中的故障。我们证明 mRMR 很容易被毒害,从而选择通常不会选择的特征。
Many machine learning models lack the consideration that an adversary can alter data at the time of training or testing. Over the past decade, the machine learning models’ vulnerability has been a concern and more secure algorithms are needed. Unfortunately, the security of feature selection (FS) remains an under-explored area. There are only a few works that address data poisoning algorithms that are targeted at embedded FS; however, data poisoning techniques targeted at information-theoretic FS do not exist. In this contribution, a novel data poisoning algorithm is proposed that targets failures in minimum Redundancy Maximum Relevance (mRMR) . We demonstrate that mRMR can be easily poisoned to select features that would not normally have been selected.