Label Sanitization against Label Flipping Poisoning Attacks

Label Sanitization against Label Flipping Poisoning Attacks
复制标题

DOI:
10.1007/978-3-030-13453-2_1
复制
发表时间:
2018-03
期刊:
ArXiv
影响因子:
--
通讯作者:
Andrea Paudice;Luis Muñoz-González;Emil C. Lupu
Andrea Paudice;Luis Muñoz-González;Emil C. Lupu
中科院分区:
其他
文献类型:
--
作者:
Andrea Paudice;Luis Muñoz-González;Emil C. Lupu

文献摘要

被引文献

相似文献

许多机器学习系统依赖于从不受信任的来源收集的数据,使学习算法暴露于数据中毒。攻击者可以在训练数据集中注入恶意数据来破坏学习过程,从而损害算法的性能,从而以有针对性或不加选择的方式产生错误。标签翻转攻击是数据中毒的一种特殊情况,攻击者可以控制分配给一部分训练点的标签。即使攻击者的能力受到限制,这些攻击已被证明是有效的显着降低系统的性能。在本文中,我们提出了一个有效的算法来执行最佳的标签翻转中毒攻击和机制来检测和重新标记可疑的数据点,减轻这种中毒攻击的影响。
Many machine learning systems rely on data collected in the wild from untrusted sources, exposing the learning algorithms to data poisoning. Attackers can inject malicious data in the training dataset to subvert the learning process, compromising the performance of the algorithm producing errors in a targeted or an indiscriminate way. Label flipping attacks are a special case of data poisoning, where the attacker can control the labels assigned to a fraction of the training points. Even if the capabilities of the attacker are constrained, these attacks have been shown to be effective to significantly degrade the performance of the system. In this paper we propose an efficient algorithm to perform optimal label flipping poisoning attacks and a mechanism to detect and relabel suspicious data points, mitigating the effect of such poisoning attacks.