CLPA: Clean-Label Poisoning Availability Attacks Using Generative Adversarial Nets
Bingyin Zhao, Yingjie Lao
摘要
Poisoning attacks are emerging threats to deep neural networks where the adversaries attempt to compromise the models by injecting malicious data points in the clean training data. Poisoning attacks target either the availability or integrity of a model. The availability attack aims to degrade the overall accuracy while the integrity attack causes misclassification only for specific instances without affecting the accuracy of clean data. Although clean-label integrity attacks are proven to be effective in recent studies, the feasibility of clean-label availability attacks remains unclear. This paper, for the first time, proposes a clean-label approach, CLPA, for the poisoning availability attack. We reveal that due to the intrinsic imperfection of classifiers, naturally misclassified inputs can be considered as a special type of poisoned data, which we refer to as "natural poisoned data''. We then propose a two-phase generative adversarial net (GAN) based poisoned data generation framework along with a triplet loss function for synthesizing clean-label poisoned samples that locate in a similar distribution as natural poisoned data. The generated poisoned data are plausible to human perception and can also bypass the singular vector decomposition (SVD) based defense. We demonstrate the effectiveness of our approach on CIFAR-10 and ImageNet dataset over a variety type of models. Codes are available at: https://github.com/bxz9200/CLPA.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Purify Unlearnable Examples via Rate-Constrained Variational AutoencodersYi Yu, Yufei Wang, Song Xia, Wenhan Yang 等ICML 2024 · 被引用 22 次
- Stable Unlearnable Example: Enhancing the Robustness of Unlearnable Examples via Stable Error-Minimizing NoiseYixin Liu, Kaidi Xu, Xun Chen, Lichao SunAAAI 2024 · 被引用 19 次
- Sharpness-Aware Data Poisoning AttackPengfei He, Han Xu, Jie Ren, Yingqian Cui 等ICLR 2024 · 被引用 10 次
- DeepHardMark: Towards Watermarking Neural Network HardwareJoseph Clements, Yingjie LaoAAAI 2022 · 被引用 10 次
- Adversarial Feature Map Pruning for BackdoorDong Huang, Qingwen BuICLR 2024 · 被引用 6 次
它引用的顶会 Paper7
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu 等S&P 2018 · 被引用 867 次
- Hidden Trigger Backdoor AttacksAniruddha Saha, Akshayvarun Subramanya, Hamed PirsiavashAAAI 2020 · 被引用 743 次
- Witches' Brew: Industrial Scale Data Poisoning via Gradient MatchingJonas Geiping, Liam H. Fowl, W. Ronny Huang, Wojciech Czaja 等ICLR 2021 · 被引用 268 次
- MetaPoison: Practical General-purpose Clean-label Data PoisoningW. Ronny Huang, Jonas Geiping, Liam Fowl, Gavin Taylor 等NeurIPS 2020 · 被引用 242 次
- Backdoor Attack with Imperceptible Input and Latent ModificationKhoa D. Doan, Yingjie Lao, Ping LiNeurIPS 2021 · 被引用 179 次
相关 Paper
- First-Order Efficient General-Purpose Clean-Label Data PoisoningTianhang Zheng, Baochun LiINFOCOM 2021 · 被引用 8 次
- Adversarial Examples Make Strong PoisonsLiam Fowl, Micah Goldblum, Ping-yeh Chiang, Jonas Geiping 等NeurIPS 2021 · 被引用 185 次
- A Theoretical Analysis of Backdoor Poisoning Attacks in Convolutional Neural NetworksBoqi Li, Weiwei LiuICML 2024 · 被引用 4 次
- Deep Partition Aggregation: Provable Defenses against General Poisoning AttacksAlexander Levine, Soheil FeiziICLR 2021 · 被引用 22 次
- Incompatibility Clustering as a Defense Against Backdoor Poisoning AttacksCharles Jin, Melinda Sun, Martin C. RinardICLR 2023 · 被引用 1 次
