Suspicion-Free Adversarial Attacks on Clustering Algorithms
Anshuman Chhabra, Abhishek Roy, Prasant Mohapatra
Abstract
Clustering algorithms are used in a large number of applications and play an important role in modern machine learningyet, adversarial attacks on clustering algorithms seem to be broadly overlooked unlike supervised learning. In this paper, we seek to bridge this gap by proposing a black-box adversarial attack for clustering models for linearly separable clusters. Our attack works by perturbing a single sample close to the decision boundary, which leads to the misclustering of multiple unperturbed samples, named spill-over adversarial samples. We theoretically show the existence of such adversarial samples for the K-Means clustering. Our attack is especially strong as (1) we ensure the perturbed sample is not an outlier, hence not detectable, and (2) the exact metric used for clustering is not known to the attacker. We theoretically justify that the attack can indeed be successful without the knowledge of the true metric. We conclude by providing empirical results on a number of datasets, and clustering algorithms. To the best of our knowledge, this is the first work that generates spill-over adversarial samples without the knowledge of the true metric ensuring that the perturbed sample is not an outlier, and theoretically proves the above. * Equal contribution and the names are in alphabetical order of second names.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1bfa45be-08a5-4669-a850-048028e9192cCited by top-tier papers7
- Learning from Limited Heterogeneous Training Data: Meta-Learning for Unsupervised Zero-Day Web Attack Detection across Web DomainsPeiyang Li, Ye Wang, Qi Li, Zhuotao Liu et al.CCS 2023 · 13 citations
- Adversarially Robust Deep Multi-View Clustering: A Novel Attack and Defense FrameworkHaonan Huang, Guoxu Zhou, Yanghang Zheng, Yuning Qiu et al.ICML 2024 · 12 citations
- On the Robustness of Deep Clustering Models: Adversarial Attacks and DefensesAnshuman Chhabra, Ashwin Sekhari, Prasant MohapatraNeurIPS 2022 · 12 citations
- Manipulating Structural Graph ClusteringWentao Li, Min Gao, Dong Wen, Hongwei Zhou et al.ICDE 2022 · 3 citations
- Robust Fair Clustering: A Novel Fairness Attack and Defense FrameworkAnshuman Chhabra, Peizhao Li, Prasant Mohapatra, Hongfu LiuICLR 2023 · 2 citations
Related papers
- On the Adversarial Robustness of Multi-Kernel ClusteringHao Yu, Weixuan Liang, Ke Liang, Suyuan Liu et al.ICML 2025
- Adversarial Learning for Robust Deep ClusteringXu Yang, Cheng Deng, Kun Wei, Junchi Yan et al.NeurIPS 2020 · 77 citations
- Differentially Private Clustering via Maximum CoverageMatthew Jones, Huy L. Nguyen, Thy Dinh NguyenAAAI 2021 · 28 citations
- Resilient k-ClusteringSara Ahmadian, MohammadHossein Bateni, Hossein Esfandiari, Silvio Lattanzi et al.KDD 2024 · 1 citation
- Minimizing Maximum Model Discrepancy for Transferable Black-box Targeted AttacksAnqi Zhao, Tong Chu, Yahao Liu, Wen Li et al.CVPR 2023
