paper-with-me

홈 › Papers

MetaPoison: Practical General-purpose Clean-label Data Poisoning

2020-04-01 · NeurIPS 2020 12 · W. Ronny Huang, Jonas Geiping, Liam Fowl, Gavin Taylor, Tom Goldstein

Data poisoning -- the process by which an attacker takes control of a model by making imperceptible changes to a subset of the training data -- is an emerging threat in the context of neural networks. Existing attacks for data poisoning neural networks have relied on hand-crafted heuristics, because solving the poisoning problem directly via bilevel optimization is generally thought of as intractable for deep models. We propose MetaPoison, a first-order method that approximates the bilevel problem via meta-learning and crafts poisons that fool neural networks. MetaPoison is effective: it outperforms previous clean-label poisoning methods by a large margin. MetaPoison is robust: poisoned data made for one model transfer to a variety of victim models with unknown training settings and architectures. MetaPoison is general-purpose, it works not only in fine-tuning scenarios, but also for end-to-end training from scratch, which till now hasn't been feasible for clean-label attacks with deep nets. MetaPoison can achieve arbitrary adversary goals -- like using poisons of one class to make a target image don the label of another arbitrarily chosen class. Finally, MetaPoison works in the real-world. We demonstrate for the first time successful data poisoning of models trained on the black-box Google Cloud AutoML API. Code and premade poisons are provided at https://github.com/wronnyhuang/metapoison

📄 PDF Abstract BibTeX arXiv:2004.00225

Code (2)

wronnyhuang/metapoison 공식 구현 tf
JonasGeiping/poisoning-gradient-matching pytorch

Tasks

AutoMLBilevel OptimizationData PoisoningMeta-Learning

Similar Papers 제목 키워드 기반

Generalization Bound and New Algorithm for Clean-Label Backdoor Attack

2024-06-02 · Lijia Yu, Shuang Liu, Yibo Miao, Xiao-Shan Gao 외

The generalization bound is a crucial theoretical tool for assessing the generalizability of learning methods and there exist vast literatures on generalizability of normal learning, adversarial learning, and data poison…

Backdoor AttackData PoisoningGeneralization Bounds

MultiScene: A Large-scale Dataset and Benchmark for Multi-scene Recognition in Single Aerial Images

2021-04-07 · Yuansheng Hua, Lichao Mou, Pu Jin, Xiao Xiang Zhu

Aerial scene recognition is a fundamental research problem in interpreting high-resolution aerial imagery. Over the past few years, most studies focus on classifying an image into one scene category, while in real-world …

Learning with noisy labelsScene Recognition

Invisible Clean-Label Backdoor Attacks for Generative Data Augmentation

2026-02-03 · Ting Xiang, Jinhui Zhao, Changjian Chen, Zhuo Tang arxiv

With the rapid advancement of image generative models, generative data augmentation has become an effective way to enrich training images, especially when only small-scale datasets are available. At the same time, in pra…

Data Augmentation

Poisoning the Inner Prediction Logic of Graph Neural Networks for Clean-Label Backdoor Attacks

2026-03-05 · Yuxiang Zhang, Bin Ma, Enyan Dai arxiv

Graph Neural Networks (GNNs) have achieved remarkable results in various tasks. Recent studies reveal that graph backdoor attacks can poison the GNN model to predict test nodes with triggers attached as the target class.…

Large Language Model-Assisted Cleaning of Report-Derived Labels in a Large-Scale Chest CT Dataset

2026-06-21 · Yosuke Yamagishi, Atsushi Takamatsu, Mototsugu Sato, Tomohiro Kikuchi 외 arxiv

Purpose: To evaluate whether large language model (LLM)-assisted label cleaning can identify label-report discordance in CT-RATE, a large-scale public chest CT dataset. Materials and Methods: After report-level deduplica…