Poisoning Web-Scale Training Datasets is Practical

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Carlini, Nicholas, Jagielski, Matthew, Choquette-Choo, Christopher A., Paleka, Daniel, Pearce, Will, Anderson, Hyrum, Terzis, Andreas, Thomas, Kurt, Tramèr, Florian
Natura: Preprint
Pubblicazione: 2023
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866909189993922560
author Carlini, Nicholas
Jagielski, Matthew
Choquette-Choo, Christopher A.
Paleka, Daniel
Pearce, Will
Anderson, Hyrum
Terzis, Andreas
Thomas, Kurt
Tramèr, Florian
author_facet Carlini, Nicholas
Jagielski, Matthew
Choquette-Choo, Christopher A.
Paleka, Daniel
Pearce, Will
Anderson, Hyrum
Terzis, Andreas
Thomas, Kurt
Tramèr, Florian
contents Deep learning models are often trained on distributed, web-scale datasets crawled from the internet. In this paper, we introduce two new dataset poisoning attacks that intentionally introduce malicious examples to a model's performance. Our attacks are immediately practical and could, today, poison 10 popular datasets. Our first attack, split-view poisoning, exploits the mutable nature of internet content to ensure a dataset annotator's initial view of the dataset differs from the view downloaded by subsequent clients. By exploiting specific invalid trust assumptions, we show how we could have poisoned 0.01% of the LAION-400M or COYO-700M datasets for just $60 USD. Our second attack, frontrunning poisoning, targets web-scale datasets that periodically snapshot crowd-sourced content -- such as Wikipedia -- where an attacker only needs a time-limited window to inject malicious examples. In light of both attacks, we notify the maintainers of each affected dataset and recommended several low-overhead defenses.
format Preprint
id arxiv_https___arxiv_org_abs_2302_10149
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Poisoning Web-Scale Training Datasets is Practical
Carlini, Nicholas
Jagielski, Matthew
Choquette-Choo, Christopher A.
Paleka, Daniel
Pearce, Will
Anderson, Hyrum
Terzis, Andreas
Thomas, Kurt
Tramèr, Florian
Cryptography and Security
Machine Learning
Deep learning models are often trained on distributed, web-scale datasets crawled from the internet. In this paper, we introduce two new dataset poisoning attacks that intentionally introduce malicious examples to a model's performance. Our attacks are immediately practical and could, today, poison 10 popular datasets. Our first attack, split-view poisoning, exploits the mutable nature of internet content to ensure a dataset annotator's initial view of the dataset differs from the view downloaded by subsequent clients. By exploiting specific invalid trust assumptions, we show how we could have poisoned 0.01% of the LAION-400M or COYO-700M datasets for just $60 USD. Our second attack, frontrunning poisoning, targets web-scale datasets that periodically snapshot crowd-sourced content -- such as Wikipedia -- where an attacker only needs a time-limited window to inject malicious examples. In light of both attacks, we notify the maintainers of each affected dataset and recommended several low-overhead defenses.
title Poisoning Web-Scale Training Datasets is Practical
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2302.10149