Fine tuning lasso in an adversarial environment against gradient attacks

Fine tuning lasso in an adversarial environment against gradient attacks
复制标题

在对抗环境中微调套索以对抗梯度攻击

DOI:
--
复制
发表时间:
2017
期刊:
IEEE Symposium Series on Computational Intelligence
影响因子:
--
通讯作者:
Ashley Prater
Ashley Prater
中科院分区:
--
文献类型:
--
作者:
G. Ditzler;Ashley Prater

文献摘要

被引文献

相似文献

机器学习和数据挖掘算法通常假设训练和测试数据是从相同的固定概率分布中采样的;然而,这种违反行为在实践中却经常被违反。域适应领域解决了两个域之间的固定概率假设被违反的情况;然而,两个领域(训练/源和测试/目标)之间的差异可能无法预先知道。最近有人在解决有对手的情况下的学习问题,我们将其表述为领域适应问题,以构建更强大的分类器。这是因为最近在学习环境中发现对手的发现,使得分类器及其预处理阶段的整体安全性受到质疑。对抗性训练(和测试)数据对攻击者有机会“毒害”训练或“逃避”测试数据集以实现不符合分类器最佳利益的目标的场景构成严重威胁。最近的工作已经开始显示对抗性数据对几个分类器的影响;然而,在对抗性学习研究的改进中,对手对数据预处理(即降维或特征选择)相关方面的影响被广泛忽视。此外,变量选择是任何数据分析的重要组成部分,已被证明特别容易受到了解该任务的攻击者的攻击。在这项工作中,我们通过考虑对抗性数据的影响以及如何通过优化减轻其影响,探索在对抗性学习环境中学习弹性分类模型的途径。我们的模型形成了一个单一的凸优化问题,该问题使用来自源域的标记训练数据和对抗组件的模型的已知弱点。我们在合成数据上对所提出的方法进行了基准测试,并展示了分类准确性和倾斜不敏感统计数据之间的权衡。
Machine learning and data mining algorithms typically assume that the training and testing data are sampled from the same fixed probability distribution; however, this violation is often violated in practice. The field of domain adaptation addresses the situation where this assumption of a fixed probability between the two domains is violated; however, the difference between the two domains (training/source and testing/target) may not be known a priori. There has been a recent thrust in addressing the problem of learning in the presence of an adversary, which we formulate as a problem of domain adaption to build a more robust classifier. This is because the overall security of classifiers and their preprocessing stages have been called into question with the recent findings of adversaries in a learning setting. Adversarial training (and testing) data pose a serious threat to scenarios where an attacker has the opportunity to “poison” the training or “evade” on the testing data set(s) in order to achieve something that is not in the best interest of the classifier. Recent work has begun to show the impact of adversarial data on several classifiers; however, the impact of the adversary on aspects related to preprocessing of data (i.e., dimensionality reduction or feature selection) has widely been ignored in the revamp of adversarial learning research. Furthermore, variable selection, which is a vital component to any data analysis, has been shown to be particularly susceptible under an attacker that has knowledge of the task. In this work, we explore avenues for learning resilient classification models in the adversarial learning setting by considering the effects of adversarial data and how to mitigate its effects through optimization. Our model forms a single convex optimization problem that uses the labeled training data from the source domain and known weaknesses of the model for an adversarial component. We benchmark the proposed approach on synthetic data and show the trade-off between classification accuracy and skew-insensitive statistics.