arXiv:2509.22113cs.LG2025-09

提出一种新方法,让回归模型更抗恶意数据干扰。

Countering adversarial evasion in regression analysis

  • 用悲观双层优化建模对抗性扰动,不依赖凸性假设。
  • 首次将该框架拓展至回归任务,提升模型鲁棒性。
  • 适合安全敏感场景如金融预测、医疗诊断的模型防护。

对抗性机器学习挑战了预测模型在训练与部署过程中分布一致性的假设。尤其在对抗性逃逸场景中,攻击者会调整输入数据以操纵已建立预测模型的结果,此类问题常见于垃圾邮件过滤、恶意软件检测和伪造图像生成等应用,要求安全机制持续更新以应对不断进化的恶意数据。博弈论模型已被证明能有效建模此类场景,从而训练出对敌手具备韧性的预测器。近期,基于悲观双层优化的方法因其无需假设敌手最优策略的凸性与唯一性,展现出对分类器的有效防御能力。然而,该方法尚未被应用于回归任务。本文提出一种适用于回归场景的悲观双层优化框架,不假设敌手解的凸性或唯一性,从而为回归模型提供更强的对抗防御能力。

原文摘要 · Abstract (English)

Adversarial machine learning challenges the assumption that the underlying distribution remains consistent throughout the training and implementation of a prediction model. In particular, adversarial evasion considers scenarios where adversaries adapt their data to influence particular outcomes from established prediction models, such scenarios arise in applications such as spam email filtering, malware detection and fake-image generation, where security methods must be actively updated to keep up with the ever-improving generation of malicious data. Game theoretic models have been shown to be effective at modelling these scenarios and hence training resilient predictors against such adversaries. Recent advancements in the use of pessimistic bilevel optimsiation which remove assumptions about the convexity and uniqueness of the adversary's optimal strategy have proved to be particularly effective at mitigating threats to classifiers due to its ability to capture the antagonistic nature of the adversary. However, this formulation has not yet been adapted to regression scenarios. This article serves to propose a pessimistic bilevel optimisation program for regression scenarios which makes no assumptions on the convexity or uniqueness of the adversary's solutions.

对抗样本回归模型双层优化鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。