Robust Learning for Data Poisoning Attacks

Robust Learning for Data Poisoning Attacks
复制标题

DOI:
--
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
Yunjuan Wang;Poorya Mianjy;R. Arora
Yunjuan Wang;Poorya Mianjy;R. Arora
中科院分区:
其他
文献类型:
--
作者:
Yunjuan Wang;Poorya Mianjy;R. Arora

文献摘要

被引文献

相似文献

我们研究了随机逼近方法对数据中毒攻击的鲁棒性。我们专注于具有ReLU激活的双层神经网络,并表明在无限宽度网络诱导的RKHS中的可分性的特定概念下,具有随机梯度下降的训练(有限宽度)网络对数据中毒攻击具有鲁棒性。有趣的是,我们发现,除了一个下限的网络的宽度,这是在文献中的标准,我们还需要一个distributiondependent上界的宽度强大的推广。我们提供了广泛的实证评估,支持和验证我们的理论结果。
We investigate the robustness of stochastic approximation approaches against data poisoning attacks. We focus on two-layer neural networks with ReLU activations and show that under a specific notion of separability in the RKHS induced by the infinite-width network, training (finitewidth) networks with stochastic gradient descent is robust against data poisoning attacks. Interestingly, we find that in addition to a lower bound on the width of the network, which is standard in the literature, we also require a distributiondependent upper bound on the width for robust generalization. We provide extensive empirical evaluations that support and validate our theoretical results.