Data poisoning against information-theoretic feature selection

Data poisoning against information-theoretic feature selection
复制标题

针对信息论特征选择的数据中毒

DOI:
10.1016/j.ins.2021.05.049
复制
发表时间:
2021
影响因子:
8.1
通讯作者:
Ditzler, G.
Ditzler, G.
中科院分区:
计算机科学1区
文献类型:
--
作者:
Liu, H.;Ditzler, G.

文献摘要

参考文献

被引文献

相似文献

机器学习中的一个典型假设是,学习模型不考虑可能破坏分类器目标的对手的存在。因此,机器学习管道在对抗性环境中表现出脆弱性。特征选择(FS)是数据分析中必不可少的预处理阶段,已广泛用于安全敏感的机器学习应用程序;然而,对抗机器学习中的FS研究在很大程度上被忽视了。最近,实证研究表明,金融服务也是脆弱的,在一个敌对的环境。在过去的十年中,虽然研究界已经做出了广泛的努力,以提高分类器的鲁棒性和开发对抗对手的对策,只有少数的贡献调查FS的行为在恶意环境中。鉴于机器学习管道越来越依赖于FS来对抗“维度灾难”和过拟合,不安全的FS可能是数据管道的“阿喀琉斯之踵”。在这方面的贡献,我们探讨了信息理论FS方法的弱点,通过设计一个通用的FS中毒算法。我们还显示了建议的中毒方法在7个信息理论FS方法的可转移性。在16个基准数据集上的实验证明了我们提出的中毒算法的有效性和可移植性的存在。
A typical assumption made in machine learning is that a learning model does not consider an adversary’s existence that can subvert a classifier’s objective. As a result, machine learning pipelines exhibit vulnerabilities in an adversarial environment. Feature Selection (FS) is an essential preprocessing stage in data analytics and has been widely used in security-sensitive machine learning applications; however, FS research in adversarial machine learning has been largely overlooked. Recently, empirical works demonstrated that the FS is also vulnerable in an adversarial environment. In the past decade, although the research community has made extensive efforts to promote the classifiers’ robustness and develop countermeasures against adversaries, only a few contributions investigated FS’s behavior in a malicious environment. Given that machine learning pipelines increasingly rely on FS to combat the “curse of dimensionality” and overfitting, insecure FS can be the “Achilles heel” of data pipelines. In this contribution, we explore the weaknesses of information-theoretic FS methods by designing a generic FS poisoning algorithm. We also show the transferability of the proposed poisoning method across seven information-theoretic FS methods. The experiments on 16 benchmark datasets demonstrate the efficacy of our proposed poisoning algorithm and the existence of transferability.
DOI: 10.1145/62212.62238
发表时间: 1993-08
期刊: SIAM J. Comput.
影响因子: --
作者:
M. Kearns;Ming Li
通讯作者: M. Kearns;Ming Li
DOI: 10.1109/ciss.2018.8362326
发表时间: 2017-04
期刊: 2018 52nd Annual Conference on Information Sciences and Systems (CISS)
影响因子: --
作者:
A. Bhagoji;Daniel Cullina;Chawin Sitawarin;Prateek Mittal
通讯作者: A. Bhagoji;Daniel Cullina;Chawin Sitawarin;Prateek Mittal
关于使用 LASSO 的特征选择的对抗鲁棒性
DOI: 10.1109/mlsp49062.2020.9231631
发表时间: 2020
期刊: IEEE International Workshop on Machine Learning for Signal Processing (MLSP
影响因子: --
作者:
Li, Fuwei;Lai, Lifeng;Cui, Shuguang
通讯作者: Cui, Shuguang
在对抗环境中微调套索以对抗梯度攻击
DOI: --
发表时间: 2017
期刊: IEEE Symposium Series on Computational Intelligence
影响因子: --
作者:
G. Ditzler;Ashley Prater
通讯作者: Ashley Prater
针对 MRMR 的数据中毒攻击
DOI: --
发表时间: 2019
期刊: IEEE International Conference on Acoustics, Speech, and Signal Processing
影响因子: --
作者:
Heng Liu;G. Ditzler
通讯作者: G. Ditzler