Proving data-poisoning robustness in decision trees
Samuel Drews, Aws Albarghouthi, Loris D'Antoni
Abstract
Machine learning models are brittle, and small changes in the training data can result in different predictions. We study the problem of proving that a prediction is robust to data poisoning, where an attacker can inject a number of malicious elements into the training set to influence the learned model. We target decision-tree models, a popular and simple class of machine learning models that underlies many complex learning techniques. We present a sound verification technique based on abstract interpretation and implement it in a tool called Antidote. Antidote abstractly trains decision trees for an intractably large space of possible poisoned datasets. Due to the soundness of our abstraction, Antidote can produce proofs that, for a given input, the corresponding prediction would not have changed had the training set been tampered with or not. We demonstrate the effectiveness of Antidote on a number of popular datasets.
• Software and its engineering → Automated static analysis; • Security and privacy → Formal methods and theory of security; • Computing methodologies → Classification and regression trees.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9ce9f4a1-a344-4125-b41b-4597397ffc26Cited by top-tier papers8
- Certifying Robustness to Programmable Data Bias in Decision TreesAnna P. Meyer, Aws Albarghouthi, Loris D'AntoniNeurIPS 2021 · 34 citations
- BagFlip: A Certified Defense Against Data PoisoningYuhao Zhang, Aws Albarghouthi, Loris D'AntoniNeurIPS 2022 · 32 citations
- Versatile Verification of Tree EnsemblesLaurens Devos, Wannes Meert, Jesse DavisICML 2021 · 16 citations
- Holding Secrets Accountable: Auditing Privacy-Preserving Machine LearningHidde Lycklama, Alexander Viand, Nicolas Küchler, Christian Knabenhans et al.USENIX Security 2024 · 11 citations
- Certifying the Fairness of KNN in the Presence of Dataset BiasYannan Li, Jingbo Wang, Chao WangCAV 2023 · 8 citations
Builds on4
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- AI2: Safety and Robustness Certification of Neural Networks with Abstract InterpretationTimon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov et al.S&P 2018 · 987 citations
- Formal Security Analysis of Neural Networks using Symbolic IntervalsShiqi Wang, Kexin Pei, Justin Whitehouse, Junfeng Yang et al.USENIX Security 2018 · 523 citations
- Abstract Interpretation of Decision Tree Ensemble ClassifiersFrancesco Ranzato, Marco ZanellaAAAI 2020 · 50 citations
Related papers
- Systematic Testing of the Data-Poisoning Robustness of KNNYannan Li, Jingbo Wang, Chao WangISSTA 2023 · 8 citations
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu et al.S&P 2018 · 867 citations
- On Robustness of Linear Classifiers to Targeted Data PoisoningNakshatra Gupta, Sumanth Prabhu S, Supratik Chakraborty, R. VenkateshAAAI 2026
- Intrinsic Certified Robustness of Bagging against Data Poisoning AttacksJinyuan Jia, Xiaoyu Cao, Neil Zhenqiang GongAAAI 2021 · 155 citations
- Verifiable Boosted Tree EnsemblesStefano Calzavara, Lorenzo Cazzaro, Claudio Lucchese, Giulio Ermanno PibiriS&P 2025
