Regularization can help mitigate poisoning attacks... with the right hyperparameters
File(s)2105.10948v1.pdf (1.03 MB)
Working paper
Author(s)
Carnerero-Cano, Javier
Muñoz-González, Luis
Spencer, Phillippa
Lupu, Emil C
Type
Working Paper
Abstract
Machine learning algorithms are vulnerable to poisoning attacks, where a
fraction of the training data is manipulated to degrade the algorithms'
performance. We show that current approaches, which typically assume that
regularization hyperparameters remain constant, lead to an overly pessimistic
view of the algorithms' robustness and of the impact of regularization. We
propose a novel optimal attack formulation that considers the effect of the
attack on the hyperparameters, modelling the attack as a \emph{minimax bilevel
optimization problem}. This allows to formulate optimal attacks, select
hyperparameters and evaluate robustness under worst case conditions. We apply
this formulation to logistic regression using $L_2$ regularization, empirically
show the limitations of previous strategies and evidence the benefits of using
$L_2$ regularization to dampen the effect of poisoning attacks.
fraction of the training data is manipulated to degrade the algorithms'
performance. We show that current approaches, which typically assume that
regularization hyperparameters remain constant, lead to an overly pessimistic
view of the algorithms' robustness and of the impact of regularization. We
propose a novel optimal attack formulation that considers the effect of the
attack on the hyperparameters, modelling the attack as a \emph{minimax bilevel
optimization problem}. This allows to formulate optimal attacks, select
hyperparameters and evaluate robustness under worst case conditions. We apply
this formulation to logistic regression using $L_2$ regularization, empirically
show the limitations of previous strategies and evidence the benefits of using
$L_2$ regularization to dampen the effect of poisoning attacks.
Date Issued
2021-05-23
Citation
2021
Publisher
arXiv
Copyright Statement
© 2021 The Author(s). This work is published with CC BY license.
License URL
Sponsor
Defence Science and Technology Laboratory (DSTL)
Identifier
http://arxiv.org/abs/2105.10948v1
Grant Number
DSTLX-1000120987
Subjects
cs.LG
cs.LG
cs.CR
stat.ML
Notes
Published at ICLR 2021 Workshop on Security and Safety in Machine Learning Systems. arXiv admin note: text overlap with arXiv:2003.00040
Publication Status
Published