Attack under Disguise: An Intelligent Data Poisoning Attack Mechanism in Crowdsourcing

Attack under Disguise: An Intelligent Data Poisoning Attack Mechanism in Crowdsourcing
复制标题

DOI:
10.1145/3178876.3186032
复制
发表时间:
2018-04
期刊:
Proceedings of the 2018 World Wide Web Conference
影响因子:
--
通讯作者:
Chenglin Miao;Qi Li;Lu Su;Mengdi Huai;Wenjun Jiang;Jing Gao
Chenglin Miao;Qi Li;Lu Su;Mengdi Huai;Wenjun Jiang;Jing Gao
中科院分区:
其他
文献类型:
--
作者:
Chenglin Miao;Qi Li;Lu Su;Mengdi Huai;Wenjun Jiang;Jing Gao

文献摘要

被引文献

相似文献

作为一种从人群中获取有用信息的有效方式,众包已经成为解决挑战性任务的一种流行范式。然而,参与的工人提供的数据并不总是可信的。在现实世界中,众包系统中可能存在恶意人员,他们出于破坏或经济回报的目的进行数据中毒攻击。虽然多数投票等数据聚合方法是在工人标签上进行的,以提高数据质量,但它们很容易受到此类攻击,因为它们对所有工人一视同仁。为了捕捉工人可靠性的变化,Dawid-Skene模型作为一种复杂的数据聚合方法在实践中得到了广泛的应用。通过使用期望最大化(EM)算法进行极大似然估计,Dawid-Skene模型可以联合估计每个工作者?S的可靠性并进行加权聚合,从而在一定程度上容忍数据中毒攻击。然而,Dawid-Skene模式仍有弱点。本文研究了基于Dawid-Skene模型的众包系统的数据中毒攻击问题。我们设计了一种智能攻击机制,在此基础上攻击者不仅可以获得最大的攻击效用,而且可以伪装攻击行为。基于真实的众包数据集进行了大量的实验,以验证所提出的机制的理想特性。
As an effective way to solicit useful information from the crowd, crowdsourcing has emerged as a popular paradigm to solve challenging tasks. However, the data provided by the participating workers are not always trustworthy. In real world, there may exist malicious workers in crowdsourcing systems who conduct the data poisoning attacks for the purpose of sabotage or financial rewards. Although data aggregation methods such as majority voting are conducted on workers» labels in order to improve data quality, they are vulnerable to such attacks as they treat all the workers equally. In order to capture the variety in the reliability of workers, the Dawid-Skene model, a sophisticated data aggregation method, has been widely adopted in practice. By conducting maximum likelihood estimation (MLE) using the expectation maximization (EM) algorithm, the Dawid-Skene model can jointly estimate each worker»s reliability and conduct weighted aggregation, and thus can tolerate the data poisoning attacks to some degree. However, the Dawid-Skene model still has weakness. In this paper, we study the data poisoning attacks against such crowdsourcing systems with the Dawid-Skene model empowered. We design an intelligent attack mechanism, based on which the attacker can not only achieve maximum attack utility but also disguise the attacking behaviors. Extensive experiments based on real-world crowdsourcing datasets are conducted to verify the desirable properties of the proposed mechanism.