REVIEW 4 cited by
Enhancing Robustness of Machine Learning Systems via Data Transformations
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
We propose the use of data transformations as a defense against evasion attacks on ML classifiers. We present and investigate strategies for incorporating a variety of data transformations including dimensionality reduction via Principal Component Analysis and data `anti-whitening' to enhance the resilience of machine learning, targeting both the classification and the training phase. We empirically evaluate and demonstrate the feasibility of linear transformations of data as a defense mechanism against evasion attacks using multiple real-world datasets. Our key findings are that the defense is (i) effective against the best known evasion attacks from the literature, resulting in a two-fold increase in the resources required by a white-box adversary with knowledge of the defense for a successful attack, (ii) applicable across a range of ML classifiers, including Support Vector Machines and Deep Neural Networks, and (iii) generalizable to multiple application domains, including image classification and human activity classification.
Forward citations
Cited by 4 Pith papers
-
Random Directional Attack for Fooling Deep Neural Networks
A hill-climbing search over randomly rotated directions generates adversarial examples with success rates competitive with gradient-based attacks, including in black-box settings.
-
Weak Links in LinkedIn: Enhancing Fake Profile Detection in the Age of LLMs
GPT-assisted adversarial retraining restores LinkedIn fake-profile detectors from a 42-52 percent false accept rate on AI-written profiles to 1-7 percent.
-
MetaAdvDet: Towards Robust Detection of Evolving Adversarial Attacks
MetaAdvDet uses a MAML-style double-network meta-learner to detect evolving adversarial attacks with one to five labeled examples, outperforming non-meta baselines on most tested benchmarks.
-
On Defending Against Label Flipping Attacks on Malware Detection Systems
A silhouette-clustering label flipping attack and two semi-supervised defenses (LSD, CSD) are proposed, with claimed accuracy gains over KSSD on Android malware datasets, but the CSD algorithm is not implementable as written.
Discussion (0). Continue with ORCID to comment.