Sharpness-Aware Data Poisoning Attack

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: He, Pengfei, Xu, Han, Ren, Jie, Cui, Yingqian, Liu, Hui, Aggarwal, Charu C., Tang, Jiliang
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912406563717120
author He, Pengfei
Xu, Han
Ren, Jie
Cui, Yingqian
Liu, Hui
Aggarwal, Charu C.
Tang, Jiliang
author_facet He, Pengfei
Xu, Han
Ren, Jie
Cui, Yingqian
Liu, Hui
Aggarwal, Charu C.
Tang, Jiliang
contents Recent research has highlighted the vulnerability of Deep Neural Networks (DNNs) against data poisoning attacks. These attacks aim to inject poisoning samples into the models' training dataset such that the trained models have inference failures. While previous studies have executed different types of attacks, one major challenge that greatly limits their effectiveness is the uncertainty of the re-training process after the injection of poisoning samples, including the re-training initialization or algorithms. To address this challenge, we propose a novel attack method called ''Sharpness-Aware Data Poisoning Attack (SAPA)''. In particular, it leverages the concept of DNNs' loss landscape sharpness to optimize the poisoning effect on the worst re-trained model. It helps enhance the preservation of the poisoning effect, regardless of the specific retraining procedure employed. Extensive experiments demonstrate that SAPA offers a general and principled strategy that significantly enhances various types of poisoning attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2305_14851
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Sharpness-Aware Data Poisoning Attack
He, Pengfei
Xu, Han
Ren, Jie
Cui, Yingqian
Liu, Hui
Aggarwal, Charu C.
Tang, Jiliang
Cryptography and Security
Recent research has highlighted the vulnerability of Deep Neural Networks (DNNs) against data poisoning attacks. These attacks aim to inject poisoning samples into the models' training dataset such that the trained models have inference failures. While previous studies have executed different types of attacks, one major challenge that greatly limits their effectiveness is the uncertainty of the re-training process after the injection of poisoning samples, including the re-training initialization or algorithms. To address this challenge, we propose a novel attack method called ''Sharpness-Aware Data Poisoning Attack (SAPA)''. In particular, it leverages the concept of DNNs' loss landscape sharpness to optimize the poisoning effect on the worst re-trained model. It helps enhance the preservation of the poisoning effect, regardless of the specific retraining procedure employed. Extensive experiments demonstrate that SAPA offers a general and principled strategy that significantly enhances various types of poisoning attacks.
title Sharpness-Aware Data Poisoning Attack
topic Cryptography and Security
url https://arxiv.org/abs/2305.14851