Proving Data-Poisoning Robustness in Decision Trees.
Machine learning models are brittle, and small changes in the training data can result in different predictions. We study the problem of proving that a prediction is robust to data poisoning, where an attacker can inject a number of malicious elements into the training set to influence the learned m...
| Publicado en: | Communications of the ACM Vol. 66; no. 2; pp. 105 - 114 |
|---|---|
| Autores principales: | , , |
| Formato: | Artículo |
| Publicado: |
Association for Computing Machinery
Feb2023
|
| Materias: | |
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=161428503&site=ehost-live header: @attributes: shortDbName: hlh uiTerm: 161428503 longDbName: Humanities International Complete uiTag: AN controlInfo: bkinfo: jinfo: jid: 00010782 ACM jtl: Communications of the ACM issn: 00010782 maglogo: N pubinfo: dt: Feb2023 vid: 66 iid: 2 pid: 68 pub: Association for Computing Machinery artinfo: ui: 161428503 10.1145/3576894 ppf: 105 ppct: 9 formats: tig: atl: Proving Data-Poisoning Robustness in Decision Trees. aug: au: Drews, Samuel Albarghouthi, Aws D'Antoni, Loris affil: University of Wisconsin-Madison, USA su: Machine learning Decision trees Data integrity Computer hacking Robust control sug: subj: Machine learning Decision trees Data integrity Computer hacking Robust control ab: Machine learning models are brittle, and small changes in the training data can result in different predictions. We study the problem of proving that a prediction is robust to data poisoning, where an attacker can inject a number of malicious elements into the training set to influence the learned model. We target decision tree models, a popular and simple class of machine learning models that underlies many complex learning techniques. We present a sound verification technique based on abstract interpretation and implement it in a tool called Antidote. Antidote abstractly trains decision trees for an intractably large space of possible poisoned datasets. Due to the soundness of our abstraction, Antidote can produce proofs that, for a given input, the corresponding prediction would not have changed had the training set been tampered with or not. We demonstrate the effectiveness of Antidote on a number of popular datasets. pubtype: Periodical doctype: Article src: R language: English refInfo: copyright: @attributes: flag: Y dt: @attributes: year: 2023 holdings: @attributes: islocal: N |
|---|