An Optimal Control View of Adversarial Machine Learning
arXiv:1811.04422
Abstract
I describe an optimal control view of adversarial machine learning, where the dynamical system is the machine learner, the input are adversarial actions, and the control costs are defined by the adversary's goals to do harm and be hard to detect. This view encompasses many types of adversarial machine learning, including test-item attacks, training-data poisoning, and adversarial reward shaping. The view encourages adversarial machine learning researcher to utilize advances in control theory and reinforcement learning.
References in corpus (3)
Cited by in corpus (5)
- Policy Teaching via Environment Poisoning: Training-time Adversarial Attacks against Reinforcement Learning
- Online Data Poisoning Attack
- Finite-Time Convergence of Continuous-Time Optimization Algorithms via Differential Inclusions
- Learning-based attacks in Cyber-Physical Systems: Exploration, Detection, and Control Cost trade-offs
- Teaching an Active Learner with Contrastive Examples