Data Poisoning against Differentially-Private Learners: Attacks and Defenses
arXiv:1903.09860
Abstract
Data poisoning attacks aim to manipulate the model produced by a learning algorithm by adversarially modifying the training set. We consider differential privacy as a defensive measure against this type of attack. We show that such learners are resistant to data poisoning attacks when the adversary is only able to poison a small number of items. However, this protection degrades as the adversary poisons more data. To illustrate, we design attack algorithms targeting objective and output perturbation learners, two standard approaches to differentially-private machine learning. Experiments show that our methods are effective when the attacker is allowed to poison sufficiently many training items.
References in corpus (1)
Cited by in corpus (7)
- Can You Really Backdoor Federated Learning?
- Privacy-Preserving Machine Learning: Methods, Challenges and Directions
- Auditing Differentially Private Machine Learning: How Private is Private SGD?
- On the Effectiveness of Mitigating Data Poisoning Attacks with Gradient Shaping
- DP-InstaHide: Provably Defusing Poisoning and Backdoor Attacks with Differentially Private Data Augmentations
- Curse or Redemption? How Data Heterogeneity Affects the Robustness of Federated Learning
- Data Poisoning Attacks on Neighborhood-based Recommender Systems