资源论文A Unified Framework for Data Poisoning Attack to Graph-based Semi-supervised Learning

A Unified Framework for Data Poisoning Attack to Graph-based Semi-supervised Learning

2020-02-26 | |  75 |   41 |   0

Abstract

In this paper, we proposed a general framework for data poisoning attacks to graphbased semi-supervised learning (G-SSL). In this framework, we first unify different tasks, goals and constraints into a single formula for data poisoning attack in GSSL, then we propose two specialized algorithms to efficiently solve two important cases — poisoning regression tasks under 图片.png-norm constraint and classification tasks under 图片.png -norm constraint. In the former case, we transform it into a nonconvex trust region problem and show that our gradient-based algorithm with delicate initialization and update scheme finds the (globally) optimal perturbation. For the latter case, although it is an NP-hard integer programming problem, we propose a probabilistic solver that works much better than the classical greedy method. Lastly, we test our framework on real datasets and evaluate the robustness of G-SSL algorithms. For instance, on the MNIST binary classification problem (50000 training data with 50 labeled), flipping two labeled data is enough to make the model perform like random guess (around 50% error).

上一篇:Assessing Social and Intersectional Biases in Contextualized Word Representations

下一篇:Graph Agreement Models for Semi-Supervised Learning

用户评价
全部评价

热门资源

  • The Variational S...

    Unlike traditional images which do not offer in...

  • Learning to Predi...

    Much of model-based reinforcement learning invo...

  • Stratified Strate...

    In this paper we introduce Stratified Strategy ...

  • A Mathematical Mo...

    Direct democracy, where each voter casts one vo...

  • Rating-Boosted La...

    The performance of a recommendation system reli...