paper

Geometric Algorithms for -NN Poisoning

arXiv:2306.12377

Abstract

We propose a label poisoning attack on geometric data sets against -nearest neighbor classification. We provide an algorithm that can compute an -additive approximation of the optimal poisoning in time for a given data set , where . Our algorithm achieves its objectives through the application of multi-scale random partitions.

14 pages, 1 figure

Geometric Algorithms for $k$-NN Poisoning · wovepaper