针对隐蔽攻击,提出带检测器的线性模型切换机制。
Adversarial Training of Linear Models under Stealthy Attacks

- 用检测器触发模型切换,让攻击者难以察觉。
- 推导出线性模型对抗风险的凸优化形式,可控制性能权衡。
- 在真实与合成数据上验证,部分受攻时仍表现更优。
预测模型广泛应用于多个领域,但易受虚假数据注入攻击。现有检测方案与对抗训练方法对隐蔽攻击缺乏保障。为此,本文提出一种基于检测器的切换模型,其中最优攻击策略具有隐蔽性。针对线性预测模型,推导出对抗风险的凸优化形式。该模型引入受保护特征,并通过超参数建模攻击概率,实现干净数据与受攻数据场景下的性能权衡。在真实和合成数据上的数值模拟表明,即使攻击概率设定有误,模型在部分受攻数据上仍表现出更优性能。
原文摘要 · Abstract (English)
Predictive models are widely used in many fields, but are vulnerable to false data injection attacks. To address this, detection schemes and adversarial training have been proposed, but such approaches lack guarantees against stealthy attacks. We therefore propose a detector-based switched model, in which optimal attack strategies are stealthy. For linear prediction models, we derive a convex formulation of the resulting adversarial risk. The model incorporates protected features and introduces a hyperparameter modelling attack probability, enabling an explicit performance trade-off between clean and attacked data regimes. Numerical simulations on real and synthetic data show improved performance on partially attacked data, even for misspecified attack probabilities.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。