Mole Recruitment: Poisoning of Image Classifiers via Selective Batch Sampling
In this work, we present a data poisoning attack that confounds machine learning models without any manipulation of the image or label. This is achieved by simply leveraging the most confounding natural samples found within the training data itself, in a new form of a targeted attack coined "Mole Recruitment." We define moles as the training samples of a class that appear most similar to samples of another class, and show that simply restructuring training batches with an optimal number of moles can lead to significant degradation in the performance of the targeted class. We show the efficacy of this novel attack in an offline setting across several standard image classification datasets, and demonstrate the real-world viability of this attack in a continual learning (CL) setting. Our analysis reveals that state-of-the-art models are susceptible to Mole Recruitment, thereby exposing a previously undetected vulnerability of image classifiers.
Code (1)
Tasks
Continual LearningData Poisoningimage-classificationImage ClassificationSimilar Papers 제목 키워드 기반
Hierarchical Selective Recruitment in Linear-Threshold Brain Networks, Part II: Multi-Layer Dynamics and Top-Down Recruitment
Goal-driven selective attention (GDSA) is a remarkable function that allows the complex dynamical networks of the brain to support coherent perception and cognition. Part I of this two-part paper proposes a new control-t…
Attacks against Ranking Algorithms with Text Embeddings: a Case Study on Recruitment Algorithms
Recently, some studies have shown that text classification tasks are vulnerable to poisoning and evasion attacks. However, little work has investigated attacks against decision making algorithms that use text embeddings,…
Decision MakingSentencetext-classificationText ClassificationSelective Poisoning Attack on Deep Neural Networks
Studies related to pattern recognition and visualization using computer technology have been introduced. In particular, deep neural networks (DNNs) provide good performance for image, speech, and pattern recognition. How…
ML Attack Models: Adversarial Attacks and Data Poisoning Attacks
Many state-of-the-art ML models have outperformed humans in various tasks such as image classification. With such outstanding performance, ML models are widely used today. However, the existence of adversarial attacks an…
Adversarial AttackData Poisoningimage-classificationImage ClassificationSystematic Evaluation of Backdoor Data Poisoning Attacks on Image Classifiers
Backdoor data poisoning attacks have recently been demonstrated in computer vision research as a potential safety risk for machine learning (ML) systems. Traditional data poisoning attacks manipulate training data to ind…
Data Poisoning