提出隐蔽投毒攻击新方法,可绕过现有防御机制。
Stealthy Poisoning Attacks Bypass Defenses in Regression Settings
- 设计兼顾隐蔽性与效果的最优投毒策略。
- 新方法能有效绕过当前最先进的防御系统。
- 适合关注模型安全与鲁棒性的研究人员。
回归模型广泛应用于工业流程、工程及自然科学领域,但其对投毒攻击的鲁棒性研究不足。现有研究多基于不切实际的威胁模型,实用性受限。本文提出一种新的最优隐蔽攻击形式化方法,考虑不同隐蔽程度,并证明该方法可绕过当前最先进的防御机制。此外,提出基于目标归一化的评估方法,以衡量有效性与可检测性之间的权衡。最后,开发了一种新型防御方法(BayesClean),在攻击隐蔽且投毒样本数量较多时,性能优于以往防御方案。
原文摘要 · Abstract (English)
Regression models are widely used in industrial processes, engineering, and in natural and physical sciences, yet their robustness to poisoning has received less attention. When it has, studies often assume unrealistic threat models and are thus less useful in practice. In this paper, we propose a novel optimal stealthy attack formulation that considers different degrees of detectability and show that it bypasses state-of-the-art defenses. We further propose a new methodology based on normalization of objectives to evaluate different trade-offs between effectiveness and detectability. Finally, we develop a novel defense (BayesClean) against stealthy attacks. BayesClean improves on previous defenses when attacks are stealthy and the number of poisoning points is significant.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。