Support Vector Machines under Adversarial Label Contamination
arXiv:2206.00352 · doi:10.1016/j.neucom.2014.08.081
Abstract
Machine learning algorithms are increasingly being applied in security-related tasks such as spam and malware detection, although their security properties against deliberate attacks have not yet been widely understood. Intelligent and adaptive attackers may indeed exploit specific vulnerabilities exposed by machine learning techniques to violate system security. Being robust to adversarial data manipulation is thus an important, additional requirement for machine learning algorithms to successfully operate in adversarial settings. In this work, we evaluate the security of Support Vector Machines (SVMs) to well-crafted, adversarial label noise attacks. In particular, we consider an attacker that aims to maximize the SVM's classification error by flipping a number of labels in the training data. We formalize a corresponding optimal attack strategy, and solve it by means of heuristic approaches to keep the computational complexity tractable. We report an extensive experimental analysis on the effectiveness of the considered attacks against linear and non-linear SVMs, both on synthetic and real-world datasets. We finally argue that our approach can also provide useful insights for developing more secure SVM learning algorithms, and also novel techniques in a number of related research areas, such as semi-supervised and active learning.
References in corpus (4)
Cited by in corpus (21)
- Can You Really Backdoor Federated Learning?
- Wild Patterns Reloaded: A Survey of Machine Learning Security against Training Data Poisoning
- Certified Defenses for Data Poisoning Attacks
- Launching Adversarial Attacks against Network Intrusion Detection Systems for IoT
- Data Poisoning Attacks Against Federated Learning Systems
- Label-Consistent Backdoor Attacks
- Reflection Backdoor: A Natural Backdoor Attack on Deep Neural Networks
- Online Data Poisoning Attack
- Poison as a Cure: Detecting & Neutralizing Variable-Sized Backdoor Attacks in Deep Neural Networks
- Fisher-Bures Adversary Graph Convolutional Networks
- Learning Discrete Distributions from Untrusted Batches
- Manipulating hidden-Markov-model inferences by corrupting batch data
- A Mathematical Programming approach to Binary Supervised Classification with Label Noise
- Securing Contrastive mmWave-based Human Activity Recognition against Adversarial Label Flipping
- Adversarial Learning: A Critical Review and Active Learning Study
- A Backdoor Attack against 3D Point Cloud Classifiers
- Poison Attacks against Text Datasets with Conditional Adversarially Regularized Autoencoder
- Modular Learning Component Attacks: Today's Reality, Tomorrow's Challenge
- Making Paper Reviewing Robust to Bid Manipulation Attacks
- Defending Distributed Classifiers Against Data Poisoning Attacks
- Totally Deep Support Vector Machines