Online Data Poisoning Attacks
Online Data Poisoning Attacks
复制标题
DOI:
--
复制
发表时间:
2020
期刊:
影响因子:
--
通讯作者:
Xuezhou Zhang;Laurent Lessard
中科院分区:
文献类型:
--
作者:
Xuezhou Zhang;Laurent Lessard
We study data poisoning attacks in the online learning setting, where training data arrive sequentially, and the attacker is eavesdropping the data stream and has the ability to contaminate the current data point to affect the online learning process. We formulate the optimal online attack problem as a stochastic optimal control problem, and provide a systematic solution using tools from model predictive control and deep reinforcement learning. We further provide theoretical analysis on the regret suffered by the attacker for not knowing the true data sequence. Experiments validate our control approach in generating near-optimal attacks on both supervised and unsupervised learning tasks. performance. We provided a regret analysis on the cost achieved by a realistic attacker and showed that despite the restricted knowledge, the optimality gap is upper-bounded by order of O ( n (cid:0) 1 = 2 ) , given the resource of n data samples.