How Robust Are Randomized Smoothing Based Defenses to Data Poisoning?
Akshay Mehra, Bhavya Kailkhura, Pin-Yu Chen, Jihun Hamm
摘要
Predictions of certifiably robust classifiers remain constant in a neighborhood of a point, making them resilient to test-time attacks with a guarantee. In this work, we present a previously unrecognized threat to robust machine learning models that highlights the importance of training-data quality in achieving high certified adversarial robustness. Specifically, we propose a novel bilevel optimization based data poisoning attack that degrades the robustness guarantees of certifiably robust classifiers. Unlike other poisoning attacks that reduce the accuracy of the poisoned models on a small set of target points, our attack reduces the average certified radius (ACR) of an entire target class in the dataset. Moreover, our attack is effective even when the victim trains the models from scratch using state-of-the-art robust training methods such as Gaussian data augmentation [8] , MACER [36], and SmoothAdv[29] that achieve high certified adversarial robustness. To make the attack harder to detect, we use cleanlabel poisoning points with imperceptible distortions. The effectiveness of the proposed method is evaluated by poisoning MNIST and CIFAR10 datasets and training deep neural networks using previously mentioned training methods and certifying the robustness with randomized smoothing. The ACR of the target class, for models trained on generated poison data, can be reduced by more than 30%. Moreover, the poisoned data is transferable to models trained with different training methods and models with different architectures.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Prompt Certified Machine Unlearning with Randomized Gradient Smoothing and QuantizationZijie Zhang, Yang Zhou, Xin Zhao, Tianshi Che 等NeurIPS 2022 · 被引用 56 次
- Understanding the Limits of Unsupervised Domain Adaptation via Data PoisoningAkshay Mehra, Bhavya Kailkhura, Pin-Yu Chen, Jihun HammNeurIPS 2021 · 被引用 30 次
- Accumulative Poisoning Attacks on Real-time DataTianyu Pang, Xiao Yang, Yinpeng Dong, Hang Su 等NeurIPS 2021 · 被引用 25 次
- On-the-fly Improving Performance of Deep Code Models via Input DenoisingZhao Tian, Junjie Chen, Xiangyu ZhangASE 2023 · 被引用 8 次
- SoK: Certified Robustness for Deep Neural NetworksLinyi Li, Tao Xie, Bo LiS&P 2023
它引用的顶会 Paper4
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu 等S&P 2019 · 被引用 1,022 次
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu 等S&P 2018 · 被引用 867 次
- Automatic Perturbation Analysis for Scalable Certified Robustness and BeyondKaidi Xu, Zhouxing Shi, Huan Zhang, Yihan Wang 等NeurIPS 2020 · 被引用 415 次
- MetaPoison: Practical General-purpose Clean-label Data PoisoningW. Ronny Huang, Jonas Geiping, Liam Fowl, Gavin Taylor 等NeurIPS 2020 · 被引用 242 次
相关 Paper
- Certified Robustness to Label-Flipping Attacks via Randomized SmoothingElan Rosenfeld, Ezra Winston, Pradeep Ravikumar, J. Zico KolterICML 2020 · 被引用 182 次
- On Robustness of Linear Classifiers to Targeted Data PoisoningNakshatra Gupta, Sumanth Prabhu S, Supratik Chakraborty, R. VenkateshAAAI 2026
- Naive Bayes Classifiers over Missing Data: Decision and PoisoningSong Bian, Xiating Ouyang, Zhiwei Fan, Paraschos KoutrisICML 2024 · 被引用 5 次
- Provable Robustness against Wasserstein Distribution Shifts via Input RandomizationAounon Kumar, Alexander Levine, Tom Goldstein, Soheil FeiziICLR 2023
- Intrinsic Certified Robustness of Bagging against Data Poisoning AttacksJinyuan Jia, Xiaoyu Cao, Neil Zhenqiang GongAAAI 2021 · 被引用 155 次
