Hyperparameter learning under data poisoning: analysis of the influence of regularization via multiobjective bilevel optimization
File(s)
Author(s)
Carnerero Cano, Javier
Munoz Gonzalez, Luis
Spencer, Phillippa
Lupu, Emil C
Type
Journal Article
Abstract
Machine Learning (ML) algorithms are vulnerable to poisoning attacks, where a fraction of the training data is manipulated to deliberately degrade the algorithms' performance. Optimal attacks can be formulated as bilevel optimization problems and help to assess their robustness in worst-case scenarios. We show that current approaches, which typically assume that hyperparameters remain constant, lead to an overly pessimistic view of the algorithms' robustness and of the impact of regularization. We propose a novel optimal attack formulation that considers the effect of the attack on the hyperparameters and models the attack as a multiobjective bilevel optimization problem. This allows to formulate optimal attacks, learn hyperparameters and evaluate robustness under worst-case conditions. We apply this attack formulation to several ML classifiers using L₂ and L₁ regularization. Our evaluation on multiple datasets shows that choosing an "a priori" constant value for the regularization hyperparameter can be detrimental to the performance of the algorithms. This confirms the limitations of previous strategies and evidences the benefits of using L₂ and L₁ regularization to dampen the effect of poisoning attacks, when hyperparameters are learned using a small trusted dataset. Additionally, our results show that the use of regularization plays an important robustness and stability role in complex models, such as Deep Neural Networks, where the attacker can have more flexibility to manipulate the decision boundary.
Date Issued
2024-11-01
Date Acceptance
2023-04-22
Citation
IEEE Transactions on Neural Networks and Learning Systems, 2024, 35 (11), pp.16008-16022
ISSN
1045-9227
Publisher
Institute of Electrical and Electronics Engineers
Start Page
16008
End Page
16022
Journal / Book Title
IEEE Transactions on Neural Networks and Learning Systems
Volume
35
Issue
11
Copyright Statement
Copyright © 2023 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.
Subjects
adversarial machine learning
bilevel optimization
data poisoning attacks
hyperparameter optimization
regularization
Publication Status
Published
Date Publish Online
2023-08-30