PACE: Poisoning Attacks on Learned Cardinality Estimation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Jintao, Zhang, Chao, Li, Guoliang, Chai, Chengliang
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929513535897600
author Zhang, Jintao
Zhang, Chao
Li, Guoliang
Chai, Chengliang
author_facet Zhang, Jintao
Zhang, Chao
Li, Guoliang
Chai, Chengliang
contents Cardinality estimation (CE) plays a crucial role in database optimizer. We have witnessed the emergence of numerous learned CE models recently which can outperform traditional methods such as histograms and samplings. However, learned models also bring many security risks. For example, a query-driven learned CE model learns a query-to-cardinality mapping based on the historical workload. Such a learned model could be attacked by poisoning queries, which are crafted by malicious attackers and woven into the historical workload, leading to performance degradation of CE. In this paper, we explore the potential security risks in learned CE and study a new problem of poisoning attacks on learned CE in a black-box setting. Experiments show that PACE reduces the accuracy of the learned CE models by 178 times, leading to a 10 times decrease in the end-to-end performance of the target database.
format Preprint
id arxiv_https___arxiv_org_abs_2409_15990
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle PACE: Poisoning Attacks on Learned Cardinality Estimation
Zhang, Jintao
Zhang, Chao
Li, Guoliang
Chai, Chengliang
Databases
Cryptography and Security
Cardinality estimation (CE) plays a crucial role in database optimizer. We have witnessed the emergence of numerous learned CE models recently which can outperform traditional methods such as histograms and samplings. However, learned models also bring many security risks. For example, a query-driven learned CE model learns a query-to-cardinality mapping based on the historical workload. Such a learned model could be attacked by poisoning queries, which are crafted by malicious attackers and woven into the historical workload, leading to performance degradation of CE. In this paper, we explore the potential security risks in learned CE and study a new problem of poisoning attacks on learned CE in a black-box setting. Experiments show that PACE reduces the accuracy of the learned CE models by 178 times, leading to a 10 times decrease in the end-to-end performance of the target database.
title PACE: Poisoning Attacks on Learned Cardinality Estimation
topic Databases
Cryptography and Security
url https://arxiv.org/abs/2409.15990