BagFlip: A Certified Defense against Data Poisoning
BagFlip: A Certified Defense against Data Poisoning
复制标题
DOI:
10.48550/arxiv.2205.13634
复制
发表时间:
2022-05
期刊:
影响因子:
--
通讯作者:
Yuhao Zhang;Aws Albarghouthi;Loris D'antoni
中科院分区:
文献类型:
--
作者:
Yuhao Zhang;Aws Albarghouthi;Loris D'antoni
Machine learning models are vulnerable to data-poisoning attacks, in which an attacker maliciously modifies the training set to change the prediction of a learned model. In a trigger-less attack, the attacker can modify the training set but not the test inputs, while in a backdoor attack the attacker can also modify test inputs. Existing model-agnostic defense approaches either cannot handle backdoor attacks or do not provide effective certificates (i.e., a proof of a defense). We present BagFlip, a model-agnostic certified approach that can effectively defend against both trigger-less and backdoor attacks. We evaluate BagFlip on image classification and malware detection datasets. BagFlip is equal to or more effective than the state-of-the-art approaches for trigger-less attacks and more effective than the state-of-the-art approaches for backdoor attacks.