Active Learning Under Malicious Mislabeling and Poisoning Attacks
arXiv:2101.00157
Abstract
Deep neural networks usually require large labeled datasets for training to achieve state-of-the-art performance in many tasks, such as image classification and natural language processing. Although a lot of data is created each day by active Internet users, most of these data are unlabeled and are vulnerable to data poisoning attacks. In this paper, we develop an efficient active learning method that requires fewer labeled instances and incorporates the technique of adversarial retraining in which additional labeled artificial data are generated without increasing the budget of the labeling. The generated adversarial examples also provide a way to measure the vulnerability of the model. To check the performance of the proposed method under an adversarial setting, i.e., malicious mislabeling and data poisoning attacks, we perform an extensive evaluation on the reduced CIFAR-10 dataset, which contains only two classes: airplane and frog. Our experimental results demonstrate that the proposed active learning method is efficient for defending against malicious mislabeling and data poisoning attacks. Specifically, whereas the baseline active learning method based on the random sampling strategy performs poorly (about 50%) under a malicious mislabeling attack, the proposed active learning method can achieve the desired accuracy of 89% using only one-third of the dataset on average.
2021 IEEE Global Communications Conference (GLOBECOM)
References in corpus (10)
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- NIPS 2016 Tutorial: Generative Adversarial Networks
- BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain
- A Field Guide to Forward-Backward Splitting with a FASTA Implementation
- Adversarial Active Learning for Deep Networks: a Margin Based Approach
- Transferable Clean-Label Poisoning Attacks on Deep Neural Nets
- Generative Adversarial Active Learning
- Provably Minimally-Distorted Adversarial Examples
- libact: Pool-based Active Learning in Python
- CIFAR10 to Compare Visual Recognition Performance between Deep Neural Networks and Humans