主动学习中,攻击者可借采集函数植入隐蔽后门,成功率高达94%
Selection-Based Vulnerabilities: Clean-Label Backdoor Attacks in Active Learning
- 利用采集函数特性,生成难以察觉的污染数据
- 0.5%-1.0%污染率下攻击成功率最高达94%
- 适合关注主动学习安全性的研究人员与应用者
主动学习(Active Learning, AL)作为一种高效的标签学习范式,广泛应用于资源受限场景。其成功依赖于采集函数,用于筛选最具价值的数据进行标注。然而,一个关键问题仍未解决:主动学习是否安全?本文提出ALA框架,首次将采集函数作为污染攻击面,揭示主动学习的脆弱性。具体而言,ALA优化不可察觉的污染输入,使其在采集函数中表现出高不确定性得分,从而提高被选中的概率。我们在三个数据集、三种采集函数及两类干净标签后门触发器上进行了广泛实验。结果表明,在极低污染预算(0.5%-1.0%)下,攻击成功率可达94%,同时保持模型性能,且对人工标注者不可检测。研究提醒:采集函数易被利用,主动学习在可信数据场景中部署需谨慎。
原文摘要 · Abstract (English)
Active learning(AL), which serves as the representative label-efficient learning paradigm, has been widely applied in resource-constrained scenarios. The achievement of AL is attributed to acquisition functions, which are designed for identifying the most important data to label. Despite this success, one question remains unanswered: is AL safe? In this work, we introduce ALA, a practical and the first framework to utilize the acquisition function as the poisoning attack surface to reveal the weakness of active learning. Specifically, ALA optimizes imperceptibly poisoned inputs to exhibit high uncertainty scores, increasing their probability of being selected by acquisition functions. To evaluate ALA, we conduct extensive experiments across three datasets, three acquisition functions, and two types of clean-label backdoor triggers. Results show that our attack can achieve high success rates (up to 94%) even under low poisoning budgets (0.5%-1.0%) while preserving model utility and remaining undetectable to human annotators. Our findings remind active learning users: acquisition functions can be easily exploited, and active learning should be deployed with caution in trusted data scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。