Label sanitization against label flipping poisoning attacks
File(s)
Author(s)
Paudice, Andrea
Muñoz-González, Luis
Lupu, Emil C
Type
Conference Paper
Abstract
Many machine learning systems rely on data collected in the
wild from untrusted sources, exposing the learning algorithms to data
poisoning. Attackers can inject malicious data in the training dataset
to subvert the learning process, compromising the performance of the
algorithm producing errors in a targeted or an indiscriminate way. Label
flipping attacks are a special case of data poisoning, where the attacker
can control the labels assigned to a fraction of the training points. Even
if the capabilities of the attacker are constrained, these attacks have
been shown to be effective to significantly degrade the performance of
the system. In this paper we propose an efficient algorithm to perform
optimal label flipping poisoning attacks and a mechanism to detect and
relabel suspicious data points, mitigating the effect of such poisoning
attacks.
wild from untrusted sources, exposing the learning algorithms to data
poisoning. Attackers can inject malicious data in the training dataset
to subvert the learning process, compromising the performance of the
algorithm producing errors in a targeted or an indiscriminate way. Label
flipping attacks are a special case of data poisoning, where the attacker
can control the labels assigned to a fraction of the training points. Even
if the capabilities of the attacker are constrained, these attacks have
been shown to be effective to significantly degrade the performance of
the system. In this paper we propose an efficient algorithm to perform
optimal label flipping poisoning attacks and a mechanism to detect and
relabel suspicious data points, mitigating the effect of such poisoning
attacks.
Date Issued
2019-02-16
Date Acceptance
2018-08-10
Citation
Lecture Notes in Computer Science, 2019, pp.5-15
ISSN
0302-9743
Publisher
Springer Verlag
Start Page
5
End Page
15
Journal / Book Title
Lecture Notes in Computer Science
Copyright Statement
This paper is embargoed until publication.
Sponsor
Engineering & Physical Science Research Council (E
Identifier
https://link.springer.com/chapter/10.1007%2F978-3-030-13453-2_1
Grant Number
EP/N023242/1
Source
Nemesis'18. Workshop in Recent Advances in Adversarial Machine Learning
Subjects
stat.ML
stat.ML
cs.CR
cs.LG
Artificial Intelligence & Image Processing
Publication Status
Published
Start Date
2018-09-10
Finish Date
2018-09-14
Coverage Spatial
Dublin, Ireland
Date Publish Online
2019-02-16