First-Order Efficient General-Purpose Clean-Label Data Poisoning
Tianhang Zheng, Baochun Li
Abstract
As one of the recently emerged threats to Deep Learning (DL) models, clean-label data poisoning can teach DL models to make wrong predictions on specific target data, such as images or network traffic packets, by injecting a small set of poisoning data with clean labels into the training datasets. Although several clean-label poisoning methods have been developed before, they have two main limitations. First, the methods developed with bi-level optimization or influence functions usually require second-order information, leading to substantial computational overhead. Second, the methods based on feature collision are not very transferable to unseen feature spaces or generalizable to various scenarios. To address these limitations, we propose a first-order efficient general-purpose clean-label poisoning attack in this paper. In our attack, we first identify the first-order model update that can push the model towards predicting the target data as the attack targeted label. We then formulate a necessary condition based on the model update and other first-order information to optimize the poisoning data. Theoretically, we prove that our first-order poisoning method is an approximation of a second-order approach with theoretically-guaranteed performance. Empirically, extensive evaluations on image classification and network traffic classification demonstrate the outstanding efficiency, transferability, and generalizability of our poisoning method.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 746cf46e-67c6-4577-8e3c-916cd11cc0dfCited by top-tier papers4
- Amplifying Membership Exposure via Data PoisoningYufei Chen, Chao Shen, Yun Shen, Cong Wang et al.NeurIPS 2022 · 56 citations
- Poisoning Attacks on Deep Learning based Wireless Traffic PredictionTianhang Zheng, Baochun LiINFOCOM 2022 · 32 citations
- Explanation-Guided Backdoor Attacks on Model-Agnostic RF FingerprintingTianya Zhao, Xuyu Wang, Junqing Zhang, Shiwen MaoINFOCOM 2024 · 24 citations
- Data Poisoning Attacks Against Outcome Interpretations of Predictive ModelsHengtong Zhang, Jing Gao, Lu SuKDD 2021 · 21 citations
Related papers
- Witches' Brew: Industrial Scale Data Poisoning via Gradient MatchingJonas Geiping, Liam H. Fowl, W. Ronny Huang, Wojciech Czaja et al.ICLR 2021 · 268 citations
- MetaPoison: Practical General-purpose Clean-label Data PoisoningW. Ronny Huang, Jonas Geiping, Liam Fowl, Gavin Taylor et al.NeurIPS 2020 · 242 citations
- CLPA: Clean-Label Poisoning Availability Attacks Using Generative Adversarial NetsBingyin Zhao, Yingjie LaoAAAI 2022 · 31 citations
- A Theoretical Analysis of Backdoor Poisoning Attacks in Convolutional Neural NetworksBoqi Li, Weiwei LiuICML 2024 · 4 citations
- Clean-image Backdoor: Attacking Multi-label Models with Poisoned Labels OnlyKangjie Chen, Xiaoxuan Lou, Guowen Xu, Jiwei Li et al.ICLR 2023
