arXiv:2502.16737cs.LG2025-02被引 4

提出动态数据投毒攻击的可认证防护框架,提升在线学习安全性。

Keeping up with dynamic attackers: Certifying robustness to adaptive online data poisoning

  • 构建可计算动态投毒影响上限的认证框架
  • 在均值估计与二分类任务中验证了防护有效性
  • 适合关注在线学习安全性的研究者与工程师

随着基于潜在不可信用户反馈微调的基础模型日益普及,对抗性数据投毒风险加剧,亟需研究学习算法对此类攻击的鲁棒性。现有针对数据投毒的可证明认证鲁棒性研究主要聚焦于静态攻击者——在训练前一次性修改部分训练数据。然而在在线学习场景中,攻击者可观察并响应学习过程,实时注入优化攻击目标的投毒样本,其破坏力远超静态攻击。本文提出一种新型框架,用于计算动态投毒的认证影响边界,并据此设计鲁棒学习算法。我们以均值估计和二分类问题为例展示该框架的应用,并指出未来扩展方向。代码已开源于 https://github.com/Avinandan22/Certified-Robustness。

原文摘要 · Abstract (English)

The rise of foundation models fine-tuned on human feedback from potentially untrusted users has increased the risk of adversarial data poisoning, necessitating the study of robustness of learning algorithms against such attacks. Existing research on provable certified robustness against data poisoning attacks primarily focuses on certifying robustness for static adversaries who modify a fraction of the dataset used to train the model before the training algorithm is applied. In practice, particularly when learning from human feedback in an online sense, adversaries can observe and react to the learning process and inject poisoned samples that optimize adversarial objectives better than when they are restricted to poisoning a static dataset once, before the learning algorithm is applied. Indeed, it has been shown in prior work that online dynamic adversaries can be significantly more powerful than static ones. We present a novel framework for computing certified bounds on the impact of dynamic poisoning, and use these certificates to design robust learning algorithms. We give an illustration of the framework for the mean estimation and binary classification problems and outline directions for extending this in further work. The code to implement our certificates and replicate our results is available at https://github.com/Avinandan22/Certified-Robustness.

数据投毒在线学习认证鲁棒性动态攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。