5 papers · 1 filter
Understanding Variation in Subpopulation Susceptibility to Poisoning Attacks
Evan Rose, Fnu Suya, David Evans
Machine learning is susceptible to poisoning attacks, in which an attacker controls a small fraction of the training data and chooses that data with the goal of inducing some behav…
Formalizing Distribution Inference Risks
Anshuman Suri, David Evans
Property inference attacks reveal statistical properties about a training set but are difficult to distinguish from the primary purposes of statistical machine learning, which is t…
Improved Estimation of Concentration Under -Norm Distance Metrics Using Half Spaces
Jack Prescott, Xiao Zhang, David Evans
Concentration of measure has been argued to be the fundamental cause of adversarial vulnerability. Mahloujifar et al. presented an empirical way to measure the concentration of a d…
Model-Targeted Poisoning Attacks with Provable Convergence
Fnu Suya, Saeed Mahloujifar, Anshuman Suri +2
In a poisoning attack, an adversary with control over a small fraction of the training data attempts to select that data in a way that induces a corrupted model that misbehaves in…
One Neuron to Fool Them All
Anshuman Suri, David Evans
Despite vast research in adversarial examples, the root causes of model susceptibility are not well understood. Instead of looking at attack-specific robustness, we propose a notio…