从数据投毒视角分析线性求解器的扰动响应,揭示其脆弱性。
Empirical Perturbation Analysis of Linear System Solvers from a Data Poisoning Perspective
- 提出标签引导与无条件两种扰动策略,模拟投毒攻击。
- 发现不同求解器对扰动敏感度差异显著,影响解的精度。
- 为提升线性模型鲁棒性提供实证依据,适合安全方向研究者。
在机器学习中广泛应用的线性系统求解问题,当遭遇数据投毒攻击时,其求解器的响应行为具有重要安全意义。本文从投毒攻击角度重新审视线性求解器的扰动特性,重点分析输入数据误差如何影响线性回归等模型的拟合误差与解的准确性。提出两种基于不同知识水平的数据扰动方法:标签引导扰动(LP)和无条件扰动(UP),并设计相应的投毒优化策略。现有研究多从理论角度推导最坏情况下的扰动边界,且仅限于特定求解器。本文则关注真实投毒场景下,不同求解器对各类对抗扰动的响应差异,识别出最易受攻击的算法类型,为构建更鲁棒的线性求解器提供实证支持。
原文摘要 · Abstract (English)
The perturbation analysis of linear solvers applied to systems arising broadly in machine learning settings -- for instance, when using linear regression models -- establishes an important perspective when reframing these analyses through the lens of a data poisoning attack. By analyzing solvers' responses to such attacks, this work aims to contribute to the development of more robust linear solvers and provide insights into poisoning attacks on linear solvers. In particular, we investigate how the errors in the input data will affect the fitting error and accuracy of the solution from a linear system-solving algorithm under perturbations common in adversarial attacks. We propose data perturbation through two distinct knowledge levels, developing a poisoning optimization and studying two methods of perturbation: Label-guided Perturbation (LP) and Unconditioning Perturbation (UP). Existing works mainly focus on deriving the worst-case perturbation bound from a theoretical perspective, and the analysis is often limited to specific kinds of linear system solvers. Under the circumstance that the data is intentionally perturbed -- as is the case with data poisoning -- we seek to understand how different kinds of solvers react to these perturbations, identifying those algorithms most impacted by different types of adversarial attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。