Online Data Poisoning Attacks

Online Data Poisoning Attacks
复制标题

DOI:
--
复制
发表时间:
2020
期刊:
--
影响因子:
--
通讯作者:
Xuezhou Zhang;Laurent Lessard
Xuezhou Zhang;Laurent Lessard
中科院分区:
其他
文献类型:
--
作者:
Xuezhou Zhang;Laurent Lessard

文献摘要

被引文献

相似文献

我们研究了在线学习环境中的数据中毒攻击,其中训练数据顺序到达,攻击者正在窃听数据流,并有能力污染当前数据点以影响在线学习过程。我们将最优在线攻击问题表述为随机最优控制问题,并使用模型预测控制和深度强化学习工具提供系统解决方案。进一步对攻击者因不知道真实数据序列而遭受的后悔进行了理论分析。实验验证了我们的控制方法在监督和无监督学习任务中产生接近最优的攻击。性能我们提供了一个现实的攻击者所实现的成本的遗憾分析,并表明,尽管知识有限,最优性差距的上限为O(n(cid:0)1 = 2),给定的资源n个数据样本。
We study data poisoning attacks in the online learning setting, where training data arrive sequentially, and the attacker is eavesdropping the data stream and has the ability to contaminate the current data point to affect the online learning process. We formulate the optimal online attack problem as a stochastic optimal control problem, and provide a systematic solution using tools from model predictive control and deep reinforcement learning. We further provide theoretical analysis on the regret suffered by the attacker for not knowing the true data sequence. Experiments validate our control approach in generating near-optimal attacks on both supervised and unsupervised learning tasks. performance. We provided a regret analysis on the cost achieved by a realistic attacker and showed that despite the restricted knowledge, the optimality gap is upper-bounded by order of O ( n (cid:0) 1 = 2 ) , given the resource of n data samples.