Machine Learning Security against Data Poisoning: Are We There Yet?
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2022
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866910357669281792 |
|---|---|
| author | Cinà, Antonio Emanuele Grosse, Kathrin Demontis, Ambra Biggio, Battista Roli, Fabio Pelillo, Marcello |
| author_facet | Cinà, Antonio Emanuele Grosse, Kathrin Demontis, Ambra Biggio, Battista Roli, Fabio Pelillo, Marcello |
| contents | The recent success of machine learning (ML) has been fueled by the increasing availability of computing power and large amounts of data in many different applications. However, the trustworthiness of the resulting models can be compromised when such data is maliciously manipulated to mislead the learning process. In this article, we first review poisoning attacks that compromise the training data used to learn ML models, including attacks that aim to reduce the overall performance, manipulate the predictions on specific test samples, and even implant backdoors in the model. We then discuss how to mitigate these attacks using basic security principles, or by deploying ML-oriented defensive mechanisms. We conclude our article by formulating some relevant open challenges which are hindering the development of testing methods and benchmarks suitable for assessing and improving the trustworthiness of ML models against data poisoning attacks |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2204_05986 |
| institution | arXiv |
| publishDate | 2022 |
| record_format | arxiv |
| spellingShingle | Machine Learning Security against Data Poisoning: Are We There Yet? Cinà, Antonio Emanuele Grosse, Kathrin Demontis, Ambra Biggio, Battista Roli, Fabio Pelillo, Marcello Cryptography and Security Computer Vision and Pattern Recognition The recent success of machine learning (ML) has been fueled by the increasing availability of computing power and large amounts of data in many different applications. However, the trustworthiness of the resulting models can be compromised when such data is maliciously manipulated to mislead the learning process. In this article, we first review poisoning attacks that compromise the training data used to learn ML models, including attacks that aim to reduce the overall performance, manipulate the predictions on specific test samples, and even implant backdoors in the model. We then discuss how to mitigate these attacks using basic security principles, or by deploying ML-oriented defensive mechanisms. We conclude our article by formulating some relevant open challenges which are hindering the development of testing methods and benchmarks suitable for assessing and improving the trustworthiness of ML models against data poisoning attacks |
| title | Machine Learning Security against Data Poisoning: Are We There Yet? |
| topic | Cryptography and Security Computer Vision and Pattern Recognition |
| url | https://arxiv.org/abs/2204.05986 |