Pith. sign in

REVIEW 1 cited by

MetaPoison: Practical General-purpose Clean-label Data Poisoning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2004.00225 v2 pith:WXQCTOKP submitted 2020-04-01 cs.LG cs.AIcs.CRcs.CVstat.ML

classification cs.LGcs.AIcs.CRcs.CVstat.ML
keywords metapoisondatapoisoningclean-labelmodelsnetworksneuralpoisons
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Data poisoning -- the process by which an attacker takes control of a model by making imperceptible changes to a subset of the training data -- is an emerging threat in the context of neural networks. Existing attacks for data poisoning neural networks have relied on hand-crafted heuristics, because solving the poisoning problem directly via bilevel optimization is generally thought of as intractable for deep models. We propose MetaPoison, a first-order method that approximates the bilevel problem via meta-learning and crafts poisons that fool neural networks. MetaPoison is effective: it outperforms previous clean-label poisoning methods by a large margin. MetaPoison is robust: poisoned data made for one model transfer to a variety of victim models with unknown training settings and architectures. MetaPoison is general-purpose, it works not only in fine-tuning scenarios, but also for end-to-end training from scratch, which till now hasn't been feasible for clean-label attacks with deep nets. MetaPoison can achieve arbitrary adversary goals -- like using poisons of one class to make a target image don the label of another arbitrarily chosen class. Finally, MetaPoison works in the real-world. We demonstrate for the first time successful data poisoning of models trained on the black-box Google Cloud AutoML API. Code and premade poisons are provided at https://github.com/wronnyhuang/metapoison

Discussion (0). Sign in to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Bias reduction method for prior event rate ratio, with application to emergency department visit rates in patients with advanced cancer

    stat.ME 2025-07 conditional novelty 5.0 of 10

    The paper proposes and simulates a conditional frailty adjustment that reduces bias in prior event rate ratio estimates when event dependence is present.

Pith tools