paper-with-me

홈 › Papers

Gradient-based Data Subversion Attack Against Binary Classifiers

2021-05-31 · Rosni K Vasu, Sanjay Seetharaman, Shubham Malaviya, Manish Shukla, Sachin Lodha

Machine learning based data-driven technologies have shown impressive performances in a variety of application domains. Most enterprises use data from multiple sources to provide quality applications. The reliability of the external data sources raises concerns for the security of the machine learning techniques adopted. An attacker can tamper the training or test datasets to subvert the predictions of models generated by these techniques. Data poisoning is one such attack wherein the attacker tries to degrade the performance of a classifier by manipulating the training data. In this work, we focus on label contamination attack in which an attacker poisons the labels of data to compromise the functionality of the system. We develop Gradient-based Data Subversion strategies to achieve model degradation under the assumption that the attacker has limited-knowledge of the victim model. We exploit the gradients of a differentiable convex loss function (residual errors) with respect to the predicted label as a warm-start and formulate different strategies to find a set of data instances to contaminate. Further, we analyze the transferability of attacks and the susceptibility of binary classifiers. Our experiments show that the proposed approach outperforms the baselines and is computationally efficient.

📄 PDF Abstract BibTeX arXiv:2105.14803

Code (0)

등록된 구현이 없습니다.

Tasks

BIG-bench Machine LearningData Poisoning

Similar Papers 제목 키워드 기반

Adversarial Attacks against Binary Similarity Systems

2023-03-20 · Gianluca Capozzi, Daniele Cono D'Elia, Giuseppe Antonio Di Luna, Leonardo Querzoni

In recent years, binary analysis gained traction as a fundamental approach to inspect software and guarantee its security. Due to the exponential increase of devices running software, much research is now moving towards …

Efficient Preference Poisoning Attack on Offline RLHF

2026-05-04 · Chenye Yang, Weiyu Xu, Lifeng Lai arxiv

Offline Reinforcement Learning from Human Feedback (RLHF) pipelines such as Direct Preference Optimization (DPO) train on a pre-collected preference dataset, which makes them vulnerable to preference poisoning attack. We…

Reinforcement Learning

A test suite of prompt injection attacks for LLM-based machine translation

2024-10-07 · Antonio Valerio Miceli-Barone, Zhifan Sun

LLM-based NLP systems typically work by embedding their input data into prompt templates which contain instructions and/or in-context examples, creating queries which are submitted to a LLM, and then parsing the LLM resp…

Machine TranslationTranslationTruthfulQA

Attacking Binarized Neural Networks

2017-11-01 · ICLR 2018 1 · Angus Galloway, Graham W. Taylor, Medhat Moussa

Neural networks with low-precision weights and activations offer compelling efficiency advantages over their full-precision equivalents. The two most frequently discussed benefits of quantization are reduced memory consu…

Quantization

Evaluating the Robustness of Adversarial Defenses in Malware Detection Systems

2025-05-14 · Mostafa Jafari, Alireza Shameli-Sendi

Machine learning is a key tool for Android malware detection, effectively identifying malicious patterns in apps. However, ML-based detectors are vulnerable to evasion attacks, where small, crafted changes bypass detecti…

Adversarial AttackAdversarial RobustnessAndroid Malware DetectionMalware Detection