Pith. sign in

REVIEW

Transferable Clean-Label Poisoning Attacks on Deep Neural Nets

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1905.05897 v2 pith:Q3FUIXNZ submitted 2019-05-15 stat.ML cs.CRcs.LG

classification stat.MLcs.CRcs.LG
keywords poisoningattackattacksdatapoisontrainingtransferableachieve
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Clean-label poisoning attacks inject innocuous looking (and "correctly" labeled) poison images into training data, causing a model to misclassify a targeted image after being trained on this data. We consider transferable poisoning attacks that succeed without access to the victim network's outputs, architecture, or (in some cases) training data. To achieve this, we propose a new "polytope attack" in which poison images are designed to surround the targeted image in feature space. We also demonstrate that using Dropout during poison creation helps to enhance transferability of this attack. We achieve transferable attack success rates of over 50% while poisoning only 1% of the training set.

Discussion (0). Sign in to comment.

Pith tools