Data Poisoning against Differentially-Private Learners: Attacks and Defenses

Data Poisoning against Differentially-Private Learners: Attacks and Defenses
复制标题

DOI:
10.24963/ijcai.2019/657
复制
发表时间:
2019-03
期刊:
--
影响因子:
--
通讯作者:
Yuzhe Ma-;Xiaojin Zhu;Justin Hsu
Yuzhe Ma-;Xiaojin Zhu;Justin Hsu
中科院分区:
其他
文献类型:
--
作者:
Yuzhe Ma-;Xiaojin Zhu;Justin Hsu

文献摘要

被引文献

相似文献

数据中毒攻击的目的是通过恶意修改训练集来操纵学习算法产生的模型。我们认为差异隐私是针对此类攻击的一种防御措施。我们表明,当对手只能毒害少量物品时,私人学习者对数据中毒攻击具有抵抗力。然而,随着对手被允许毒害更多的数据,这种保护会降级。我们通过设计针对目标和输出扰动学习器的攻击算法,对这种保护进行了实证评估,这是两种不同私有机器学习的标准方法。实验表明,当攻击者被允许对足够多的训练项目下毒时,我们的方法是有效的。
Data poisoning attacks aim to manipulate the model produced by a learning algorithm by adversarially modifying the training set. We consider differential privacy as a defensive measure against this type of attack. We show that private learners are resistant to data poisoning attacks when the adversary is only able to poison a small number of items. However, this protection degrades as the adversary is allowed to poison more data. We emprically evaluate this protection by designing attack algorithms targeting objective and output perturbation learners, two standard approaches to differentially-private machine learning. Experiments show that our methods are effective when the attacker is allowed to poison sufficiently many training items.