Improved Certified Defenses against Data Poisoning with (Deterministic) Finite Aggregation
Wenxiao Wang, Alexander Levine, Soheil Feizi
摘要
Data poisoning attacks aim at manipulating model behaviors through distorting training data. Previously, an aggregation-based certified defense, Deep Partition Aggregation (DPA), was proposed to mitigate this threat. DPA predicts through an aggregation of base classifiers trained on disjoint subsets of data, thus restricting its sensitivity to dataset distortions. In this work, we propose an improved certified defense against general poisoning attacks, namely Finite Aggregation. In contrast to DPA, which directly splits the training set into disjoint subsets, our method first splits the training set into smaller disjoint subsets and then combines duplicates of them to build larger (but not disjoint) subsets for training base classifiers. This reduces the worst-case impacts of poison samples and thus improves certified robustness bounds. In addition, we offer an alternative view of our method, bridging the designs of deterministic and stochastic aggregation-based certified defenses. Empirically, our proposed Finite Aggregation consistently improves certificates on MNIST, CIFAR-10, and GTSRB, boosting certified fractions by up to 3.05%, 3.87% and 4.77%, respectively, while keeping the same clean accuracies as DPA's, effectively establishing a new state of the art in (pointwise) certified robustness against data poisoning.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper24
- Rethinking Backdoor AttacksAlaa Khaddaj, Guillaume Leclerc, Aleksandar Makelov, Kristian Georgiev 等ICML 2023 · 被引用 42 次
- BagFlip: A Certified Defense Against Data PoisoningYuhao Zhang, Aws Albarghouthi, Loris D'AntoniNeurIPS 2022 · 被引用 32 次
- Baffle: Hiding Backdoors in Offline Reinforcement Learning DatasetsChen Gong, Zhou Yang, Yunpeng Bai, Junda He 等S&P 2024 · 被引用 28 次
- Exploring the Limits of Model-Targeted Indiscriminate Data Poisoning AttacksYiwei Lu, Gautam Kamath, Yaoliang YuICML 2023 · 被引用 25 次
- Run-off Election: Improved Provable Defense against Data Poisoning AttacksKeivan Rezaei, Kiarash Banihashem, Atoosa Malemir Chegini, Soheil FeiziICML 2023 · 被引用 22 次
它引用的顶会 Paper10
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Hidden Trigger Backdoor AttacksAniruddha Saha, Akshayvarun Subramanya, Hamed PirsiavashAAAI 2020 · 被引用 743 次
- Witches' Brew: Industrial Scale Data Poisoning via Gradient MatchingJonas Geiping, Liam H. Fowl, W. Ronny Huang, Wojciech Czaja 等ICLR 2021 · 被引用 268 次
- Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning AttacksAvi Schwarzschild, Micah Goldblum, Arjun Gupta, John P. Dickerson 等ICML 2021 · 被引用 207 次
- Robust anomaly detection and backdoor attack detection via differential privacyMin Du, Ruoxi Jia, Dawn SongICLR 2020 · 被引用 194 次
相关 Paper
- Deep Partition Aggregation: Provable Defenses against General Poisoning AttacksAlexander Levine, Soheil FeiziICLR 2021 · 被引用 22 次
- Lethal Dose Conjecture on Data PoisoningWenxiao Wang, Alexander Levine, Soheil FeiziNeurIPS 2022 · 被引用 17 次
- Certifying Graph Neural Networks Against Label and Structure PoisoningLukas Gosch, Xichuan Chen, Yan Scholten, Stephan GünnemannICML 2026
- Intrinsic Certified Robustness of Bagging against Data Poisoning AttacksJinyuan Jia, Xiaoyu Cao, Neil Zhenqiang GongAAAI 2021 · 被引用 155 次
- Enhancing the Antidote: Improved Pointwise Certifications against Poisoning AttacksShijie Liu, Andrew C. Cullen, Paul Montague, Sarah M. Erfani 等AAAI 2023 · 被引用 7 次
