arXiv:2411.16591cs.LGstat.ML2024-11中稿 · ESANN 2025被引 4

提出对抗性数据流攻击,让模型无法检测到真实的数据漂移。

Adversarial Attacks for Drift Detection

  • 设计对抗性数据流,骗过主流漂移检测方法
  • 证明多种常见检测器在特定攻击下完全失效
  • 适合系统监控与模型可靠性研究者参考

概念漂移指随时间变化的数据分布。虽然漂移对学习模型构成挑战,需要持续适应,但也与系统监控密切相关,可用于检测故障、系统崩溃和异常行为。在此场景中,漂移检测的鲁棒性和可靠性至关重要。本文研究了常用漂移检测方案的缺陷,揭示如何构造看似无漂移但实际上持续漂移的数据流,称之为‘漂移对抗样本’。我们计算了常见检测方法下的所有可能对抗样本,并通过实证评估验证了理论发现。

原文摘要 · Abstract (English)

Concept drift refers to the change of data distributions over time. While drift poses a challenge for learning models, requiring their continual adaption, it is also relevant in system monitoring to detect malfunctions, system failures, and unexpected behavior. In the latter case, the robust and reliable detection of drifts is imperative. This work studies the shortcomings of commonly used drift detection schemes. We show how to construct data streams that are drifting without being detected. We refer to those as drift adversarials. In particular, we compute all possible adversairals for common detection schemes and underpin our theoretical findings with empirical evaluations.

漂移检测对抗攻击系统监控

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。