Pith. sign in

REVIEW 1 cited by

Poisoning Attacks with Generative Adversarial Nets

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1906.07773 v2 pith:RRKCYTJA submitted 2019-06-18 cs.LG cs.CRstat.ML

classification cs.LGcs.CRstat.ML
keywords attackspoisoninglearningadversarialdatagenerativemachinetraining
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Machine learning algorithms are vulnerable to poisoning attacks: An adversary can inject malicious points in the training dataset to influence the learning process and degrade the algorithm's performance. Optimal poisoning attacks have already been proposed to evaluate worst-case scenarios, modelling attacks as a bi-level optimization problem. Solving these problems is computationally demanding and has limited applicability for some models such as deep networks. In this paper we introduce a novel generative model to craft systematic poisoning attacks against machine learning classifiers generating adversarial training examples, i.e. samples that look like genuine data points but that degrade the classifier's accuracy when used for training. We propose a Generative Adversarial Net with three components: generator, discriminator, and the target classifier. This approach allows us to model naturally the detectability constrains that can be expected in realistic attacks and to identify the regions of the underlying data distribution that can be more vulnerable to data poisoning. Our experimental evaluation shows the effectiveness of our attack to compromise machine learning classifiers, including deep networks.

Discussion (0). Sign in to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Poisoning Behavioral-based Worker Selection in Mobile Crowdsensing using Generative Adversarial Networks

    cs.CR 2025-06 conditional novelty 5.0 of 10

    An insider can use GANs to poison behavioral worker-selection models in mobile crowdsensing, raising cancellation predictions and cutting victim payments while evading outlier detection.

Pith tools