Proving Data-Poisoning Robustness in Decision Trees.

Machine learning models are brittle, and small changes in the training data can result in different predictions. We study the problem of proving that a prediction is robust to data poisoning, where an attacker can inject a number of malicious elements into the training set to influence the learned m...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 66; no. 2; pp. 105 - 114
Autores principales: Drews, Samuel, Albarghouthi, Aws, D'Antoni, Loris
Formato: Artículo
Publicado: Association for Computing Machinery Feb2023
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=161428503&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 161428503
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        00010782
        ACM
      jtl: Communications of the ACM
      issn: 00010782
      maglogo: N
    pubinfo:
      dt: Feb2023
      vid: 66
      iid: 2
      pid: 68
      pub: Association for Computing Machinery
    artinfo:
      ui:
        161428503
        10.1145/3576894
      ppf: 105
      ppct: 9
      formats:
      tig:
        atl: Proving Data-Poisoning Robustness in Decision Trees.
      aug:
        au:
          Drews, Samuel
          Albarghouthi, Aws
          D'Antoni, Loris
        affil: University of Wisconsin-Madison, USA
      su:
        Machine learning
        Decision trees
        Data integrity
        Computer hacking
        Robust control
      sug:
        subj:
          Machine learning
          Decision trees
          Data integrity
          Computer hacking
          Robust control
      ab: Machine learning models are brittle, and small changes in the training data can result in different predictions. We study the problem of proving that a prediction is robust to data poisoning, where an attacker can inject a number of malicious elements into the training set to influence the learned model. We target decision tree models, a popular and simple class of machine learning models that underlies many complex learning techniques. We present a sound verification technique based on abstract interpretation and implement it in a tool called Antidote. Antidote abstractly trains decision trees for an intractably large space of possible poisoned datasets. Due to the soundness of our abstraction, Antidote can produce proofs that, for a given input, the corresponding prediction would not have changed had the training set been tampered with or not. We demonstrate the effectiveness of Antidote on a number of popular datasets.
      pubtype: Periodical
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2023
    holdings:
      @attributes:
        islocal: N