Evasion-Robust Classification on Binary Domains

Evasion-Robust Classification on Binary Domains
复制标题

二进制域上的规避鲁棒分类

DOI:
10.1145/3186282
复制
发表时间:
2018
影响因子:
3.6
通讯作者:
Vorobeychik, Yevgeniy
Vorobeychik, Yevgeniy
中科院分区:
计算机科学3区
文献类型:
--
作者:
Li, Bo;Vorobeychik, Yevgeniy

文献摘要

参考文献

被引文献

相似文献

分类学习的成功导致了许多将其应用于对抗环境的尝试,例如垃圾邮件和恶意软件检测。这类应用程序的核心挑战是攻击者不是静态的,而是故意逃避分类器。我们研究了对这些对手的目标进行建模的问题,以及对理性的、目标驱动的对手进行会计处理的算法问题。我们首先提出了一种基于约束生成的混合整数线性规划(MILP)的通用方法。该方法首次在二元特征空间中为两类一般的对抗性规避模型计算了对抗性损失最小化的最优解。为了进一步提高可扩展性并显著推广基于milp的方法的范围,我们提出了一个原则性的迭代再训练框架,该框架可以用于任意分类器和本质上任意的攻击模型。我们证明了再训练方法,当它收敛时,最小化对抗性损失的上界。大量的实验表明,混合整数规划方法显著优于几种最先进的对抗性学习替代方法。此外,再训练框架的性能也差不多,但可扩展性要好得多。最后,我们证明了我们的方法对对抗性模型的错误规范具有鲁棒性。
The success of classification learning has led to numerous attempts to apply it in adversarial settings such as spam and malware detection. The core challenge in this class of applications is that adversaries are not static, but make a deliberate effort to evade the classifiers. We investigate both the problem of modeling the objectives of such adversaries, as well as the algorithmic problem of accounting for rational, objective-driven adversaries. We first present a general approach based on mixed-integer linear programming (MILP) with constraint generation. This approach is the first to compute an optimal solution to adversarial loss minimization for two general classes of adversarial evasion models in the context of binary feature spaces. To further improve scalability and significantly generalize the scope of the MILP-based method, we propose a principled iterative retraining framework, which can be used with arbitrary classifiers and essentially arbitrary attack models. We show that the retraining approach, when it converges, minimizes an upper bound on adversarial loss. Extensive experiments demonstrate that the mixed-integer programming approach significantly outperforms several state-of-the-art adversarial learning alternatives. Moreover, the retraining framework performs nearly as well, but scales significantly better. Finally, we show that our approach is robust to misspecifications of the adversarial model.
DOI: 10.1198/jasa.2008.s239
发表时间: 2008-06
影响因子: 3.7
作者:
David E. Tyler
通讯作者: David E. Tyler
DOI: 10.1145/62212.62238
发表时间: 1993-08
期刊: SIAM J. Comput.
影响因子: --
作者:
M. Kearns;Ming Li
通讯作者: M. Kearns;Ming Li
电子邮件过滤器规避的行为实验
DOI: 10.1609/aaai.v30i1.10061
发表时间: 2016
期刊: Cells
影响因子: 6
作者:
Liyiming Ke;Bo Li;Yevgeniy Vorobeychik
通讯作者: Yevgeniy Vorobeychik
垃圾邮件:不再仅仅针对收件箱
DOI: 10.1109/mc.2005.352
发表时间: 2005
期刊: Computer
影响因子: 2.2
作者:
Zoltán Gyöngyi;H. Garcia
通讯作者: H. Garcia
“体内”垃圾邮件过滤:KDD 面临的挑战
DOI: 10.1145/980972.980990
发表时间: 2003
期刊: SIGKDD Explor.
影响因子: --
作者:
Tom Fawcett
通讯作者: Tom Fawcett