Proving data-poisoning robustness in decision trees

Proving data-poisoning robustness in decision trees
复制标题

DOI:
10.1145/3385412.3385975
复制
发表时间:
2020-06
期刊:
Proceedings of the 41st ACM SIGPLAN Conference on Programming Language Design and Implementation
影响因子:
--
通讯作者:
Samuel Drews;Aws Albarghouthi;Loris D'antoni
Samuel Drews;Aws Albarghouthi;Loris D'antoni
中科院分区:
其他
文献类型:
--
作者:
Samuel Drews;Aws Albarghouthi;Loris D'antoni

文献摘要

被引文献

相似文献

机器学习模型是脆弱的,训练数据的小变化可能会导致不同的预测。我们研究了证明预测对数据中毒是可靠的问题的问题,攻击者可以将许多恶意元素注入训练集中以影响学习模型。我们针对决策树模型,这是一种流行而简单的机器学习模型,它是许多复杂的学习技术的基础。我们提出了一种基于抽象解释的声音验证技术,并在称为解毒剂的工具中实现它。解毒剂抽象地训练决策树,以了解可能有毒数据集的大量空间。由于我们的抽象的合理性,解毒剂可以产生证据,对于给定的输入,如果训练集被篡改,则相应的预测不会改变。我们证明了解毒剂对许多流行数据集的有效性。
Machine learning models are brittle, and small changes in the training data can result in different predictions. We study the problem of proving that a prediction is robust to data poisoning, where an attacker can inject a number of malicious elements into the training set to influence the learned model. We target decision-tree models, a popular and simple class of machine learning models that underlies many complex learning techniques. We present a sound verification technique based on abstract interpretation and implement it in a tool called Antidote. Antidote abstractly trains decision trees for an intractably large space of possible poisoned datasets. Due to the soundness of our abstraction, Antidote can produce proofs that, for a given input, the corresponding prediction would not have changed had the training set been tampered with or not. We demonstrate the effectiveness of Antidote on a number of popular datasets.