paper-with-me

홈 › Papers

Fragile Giants: Understanding the Susceptibility of Models to Subpopulation Attacks

2024-10-11 · Isha Gupta, Hidde Lycklama, Emanuel Opel, Evan Rose, Anwar Hithnawi

As machine learning models become increasingly complex, concerns about their robustness and trustworthiness have become more pressing. A critical vulnerability of these models is data poisoning attacks, where adversaries deliberately alter training data to degrade model performance. One particularly stealthy form of these attacks is subpopulation poisoning, which targets distinct subgroups within a dataset while leaving overall performance largely intact. The ability of these attacks to generalize within subpopulations poses a significant risk in real-world settings, as they can be exploited to harm marginalized or underrepresented groups within the dataset. In this work, we investigate how model complexity influences susceptibility to subpopulation poisoning attacks. We introduce a theoretical framework that explains how overparameterized models, due to their large capacity, can inadvertently memorize and misclassify targeted subpopulations. To validate our theory, we conduct extensive experiments on large-scale image and text datasets using popular model architectures. Our results show a clear trend: models with more parameters are significantly more vulnerable to subpopulation poisoning. Moreover, we find that attacks on smaller, human-interpretable subgroups often go undetected by these models. These results highlight the need to develop defenses that specifically address subpopulation vulnerabilities.

📄 PDF Abstract BibTeX arXiv:2410.08872

Code (0)

등록된 구현이 없습니다.

Tasks

Data Poisoning

Similar Papers 제목 키워드 기반

Understanding Variation in Subpopulation Susceptibility to Poisoning Attacks

2023-11-20 · Evan Rose, Fnu Suya, David Evans

Machine learning is susceptible to poisoning attacks, in which an attacker controls a small fraction of the training data and chooses that data with the goal of inducing some behavior unintended by the model developer in…

Subpopulation Data Poisoning Attacks

2020-06-24 · Matthew Jagielski, Giorgio Severi, Niklas Pousette Harger, Alina Oprea

Machine learning systems are deployed in critical settings, but they might fail in unexpected ways, impacting the accuracy of their predictions. Poisoning attacks against machine learning induce adversarial modification …

BIG-bench Machine LearningData Poisoning

On the Discredibility of Membership Inference Attacks

2022-12-06 · Shahbaz Rezaei, Xin Liu

With the wide-spread application of machine learning models, it has become critical to study the potential data leakage of models trained on sensitive data. Recently, various membership inference (MI) attacks are propose…

Exposing and Mitigating Temporal Attack in Deepfake Video Detection

2026-05-08 · Zheyuan Gu, Minghao Shao, Zhen Wang, Yusong Wang 외 arxiv

While spatiotemporal deepfake detectors achieve high AUC, our experiments reveal their susceptibility to evasion attacks. These models tend to overfit on fragile temporal spectrum cues, rather than learning robust semant…

SoK: Understanding (New) Security Issues Across AI4Code Use Cases

2025-12-20 · Qilong Wu, Taoran Li, Tianyang Zhou, Varun Chandrasekaran arxiv

AI-for-Code (AI4Code) systems are reshaping software engineering, with tools like GitHub Copilot accelerating code generation, translation, and vulnerability detection. Alongside these advances, however, security risks r…

Vulnerability DetectionAdversarial RobustnessCode TranslationCode Generation