Poisoning Web-Scale Training Datasets is Practical
Fuente:
arXiv
Salvato in:
| Autori principali: | , , , , , , , , |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2023
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
| _version_ | 1866909189993922560 |
|---|---|
| author | Carlini, Nicholas Jagielski, Matthew Choquette-Choo, Christopher A. Paleka, Daniel Pearce, Will Anderson, Hyrum Terzis, Andreas Thomas, Kurt Tramèr, Florian |
| author_facet | Carlini, Nicholas Jagielski, Matthew Choquette-Choo, Christopher A. Paleka, Daniel Pearce, Will Anderson, Hyrum Terzis, Andreas Thomas, Kurt Tramèr, Florian |
| contents | Deep learning models are often trained on distributed, web-scale datasets crawled from the internet. In this paper, we introduce two new dataset poisoning attacks that intentionally introduce malicious examples to a model's performance. Our attacks are immediately practical and could, today, poison 10 popular datasets. Our first attack, split-view poisoning, exploits the mutable nature of internet content to ensure a dataset annotator's initial view of the dataset differs from the view downloaded by subsequent clients. By exploiting specific invalid trust assumptions, we show how we could have poisoned 0.01% of the LAION-400M or COYO-700M datasets for just $60 USD. Our second attack, frontrunning poisoning, targets web-scale datasets that periodically snapshot crowd-sourced content -- such as Wikipedia -- where an attacker only needs a time-limited window to inject malicious examples. In light of both attacks, we notify the maintainers of each affected dataset and recommended several low-overhead defenses. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2302_10149 |
| institution | arXiv |
| publishDate | 2023 |
| record_format | arxiv |
| spellingShingle | Poisoning Web-Scale Training Datasets is Practical Carlini, Nicholas Jagielski, Matthew Choquette-Choo, Christopher A. Paleka, Daniel Pearce, Will Anderson, Hyrum Terzis, Andreas Thomas, Kurt Tramèr, Florian Cryptography and Security Machine Learning Deep learning models are often trained on distributed, web-scale datasets crawled from the internet. In this paper, we introduce two new dataset poisoning attacks that intentionally introduce malicious examples to a model's performance. Our attacks are immediately practical and could, today, poison 10 popular datasets. Our first attack, split-view poisoning, exploits the mutable nature of internet content to ensure a dataset annotator's initial view of the dataset differs from the view downloaded by subsequent clients. By exploiting specific invalid trust assumptions, we show how we could have poisoned 0.01% of the LAION-400M or COYO-700M datasets for just $60 USD. Our second attack, frontrunning poisoning, targets web-scale datasets that periodically snapshot crowd-sourced content -- such as Wikipedia -- where an attacker only needs a time-limited window to inject malicious examples. In light of both attacks, we notify the maintainers of each affected dataset and recommended several low-overhead defenses. |
| title | Poisoning Web-Scale Training Datasets is Practical |
| topic | Cryptography and Security Machine Learning |
| url | https://arxiv.org/abs/2302.10149 |