arXiv:2503.22759cs.CRcs.AI2025-03综述被引 34

系统梳理深度学习数据投毒攻击,揭示其原理与新趋势。

Data Poisoning in Deep Learning: A Survey

  • 从多维度分类分析数据投毒攻击的机制与设计原则
  • 首次深入探讨大语言模型中的数据投毒新挑战
  • 适合关注AI安全与可信机器学习的研究者阅读

深度学习已成为现代人工智能的核心,广泛应用于多个领域。训练数据的质量与安全性直接影响模型性能与可靠性。然而,深度学习模型在训练过程中面临严重的数据投毒威胁:攻击者通过注入恶意篡改的数据,导致模型准确率下降或行为异常。现有综述虽涵盖攻防两方面,但缺乏对深度学习数据投毒攻击的专门、深入分析。本文填补这一空白,系统梳理数据投毒攻击的多维分类,深入剖析其特性与设计原理;扩展至大语言模型(LLMs)中的数据投毒新兴问题;最后探讨关键开放挑战并提出未来研究方向。为支持进一步研究,相关资源仓库已开源:https://github.com/Pinlong-Zhao/Data-Poisoning。

原文摘要 · Abstract (English)

Deep learning has become a cornerstone of modern artificial intelligence, enabling transformative applications across a wide range of domains. As the core element of deep learning, the quality and security of training data critically influence model performance and reliability. However, during the training process, deep learning models face the significant threat of data poisoning, where attackers introduce maliciously manipulated training data to degrade model accuracy or lead to anomalous behavior. While existing surveys provide valuable insights into data poisoning, they generally adopt a broad perspective, encompassing both attacks and defenses, but lack a dedicated, in-depth analysis of poisoning attacks specifically in deep learning. In this survey, we bridge this gap by presenting a comprehensive and targeted review of data poisoning in deep learning. First, this survey categorizes data poisoning attacks across multiple perspectives, providing an in-depth analysis of their characteristics and underlying design princinples. Second, the discussion is extended to the emerging area of data poisoning in large language models(LLMs). Finally, we explore critical open challenges in the field and propose potential research directions to advance the field further. To support further exploration, an up-to-date repository of resources on data poisoning in deep learning is available at https://github.com/Pinlong-Zhao/Data-Poisoning.

数据投毒AI安全大模型深度学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。