Availability Attacks Create Shortcuts
Da Yu, Huishuai Zhang, Wei Chen, Jian Yin, Tie-Yan Liu
Abstract
Availability attacks 1 , which poison the training data with imperceptible perturbations, can make the data not exploitable by machine learning algorithms so as to prevent unauthorized use of data. In this work, we investigate why these perturbations work in principle. We are the first to unveil an important population property of the perturbations of these attacks: they are almost linearly separable when assigned with the target labels of the corresponding samples, which hence can work as shortcuts for the learning objective. We further verify that linear separability is indeed the workhorse for availability attacks. We synthesize linearly-separable perturbations as attacks and show that they are as powerful as the deliberately crafted attacks. Moreover, such synthetic perturbations are much easier to generate. For example, previous attacks need dozens of hours to generate perturbations for ImageNet while our algorithm only needs several seconds. Our finding also suggests that the shortcut learning is more widely present than previously believed as deep models would rely on shortcuts even if they are of an imperceptible scale and mixed together with the normal features. Our source code is published at https://github.com/dayu11/Availability-Attacks-Create-Shortcuts . CCS CONCEPTS • Security and privacy → Privacy protections; • Computing methodologies → Adversarial learning.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 013dfec4-ef09-4a6f-8adb-d800977f8df2Cited by top-tier papers37
- Image Shortcut Squeezing: Countering Perturbative Availability Poisons with CompressionZhuoran Liu, Zhengyu Zhao, Martha A. LarsonICML 2023 · 51 citations
- What Can We Learn from Unlearnable Datasets?Pedro Sandoval Segura, Vasu Singla, Jonas Geiping, Micah Goldblum et al.NeurIPS 2023 · 28 citations
- Exploring the Limits of Model-Targeted Indiscriminate Data Poisoning AttacksYiwei Lu, Gautam Kamath, Yaoliang YuICML 2023 · 25 citations
- Purify Unlearnable Examples via Rate-Constrained Variational AutoencodersYi Yu, Yufei Wang, Song Xia, Wenhan Yang et al.ICML 2024 · 22 citations
- UnSeg: One Universal Unlearnable Example Generator is Enough against All Image SegmentationYe Sun, Hao Zhang, Tiehua Zhang, Xingjun Ma et al.NeurIPS 2024 · 18 citations
Builds on18
- CutMix: Regularization Strategy to Train Strong Classifiers With Localizable FeaturesSangdoo Yun, Dongyoon Han, Sanghyuk Chun, Seong Joon Oh et al.ICCV 2019 · 5,843 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
- Big Self-Supervised Models are Strong Semi-Supervised LearnersTing Chen, Simon Kornblith, Kevin Swersky, Mohammad Norouzi et al.NeurIPS 2020 · 2,611 citations
- Hidden Trigger Backdoor AttacksAniruddha Saha, Akshayvarun Subramanya, Hamed PirsiavashAAAI 2020 · 743 citations
- Input-Aware Dynamic Backdoor AttackTuan Anh Nguyen, Anh Tuan TranNeurIPS 2020 · 601 citations
Related papers
- CLPA: Clean-Label Poisoning Availability Attacks Using Generative Adversarial NetsBingyin Zhao, Yingjie LaoAAAI 2022 · 31 citations
- Re-Thinking Data Availability Attacks Against Deep Neural NetworksBin Fang, Bo Li, Shuang Wu, Shouhong Ding et al.CVPR 2024
- Efficient Availability Attacks against Supervised and Contrastive Learning SimultaneouslyYihan Wang, Yifan Zhu, Xiao-Shan GaoNeurIPS 2024 · 14 citations
- Adversarial Examples Make Strong PoisonsLiam Fowl, Micah Goldblum, Ping-yeh Chiang, Jonas Geiping et al.NeurIPS 2021 · 185 citations
- Revisiting the Assumption of Latent Separability for Backdoor DefensesXiangyu Qi, Tinghao Xie, Yiming Li, Saeed Mahloujifar et al.ICLR 2023
