2020
DOI: 10.48550/arxiv.2005.00191
|View full text |Cite
Preprint
|
Sign up to set email alerts
|

Bullseye Polytope: A Scalable Clean-Label Poisoning Attack with Improved Transferability

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
4
1

Citation Types

0
19
0

Year Published

2020
2020
2022
2022

Publication Types

Select...
4
1

Relationship

1
4

Authors

Journals

citations
Cited by 6 publications
(19 citation statements)
references
References 0 publications
0
19
0
Order By: Relevance
“…Backdoor attacks. As a variant of poisoning attacks, a backdoor attack aims to mislead the model on some specific target inputs [1,24,34,76,97], or inject trigger patterns [12,30,52,70,83,86], without affecting model performance on clean test data. Backdoor attacks have a similar formulation as poisoning attacks, except that S val in Eq.…”
Section: Attacking Strategiesmentioning
confidence: 99%
“…Backdoor attacks. As a variant of poisoning attacks, a backdoor attack aims to mislead the model on some specific target inputs [1,24,34,76,97], or inject trigger patterns [12,30,52,70,83,86], without affecting model performance on clean test data. Backdoor attacks have a similar formulation as poisoning attacks, except that S val in Eq.…”
Section: Attacking Strategiesmentioning
confidence: 99%
“…So-called clean-label poisoning attacks have been recently proposed against image classification systems for the first time [1,27,38], wherein the adversary has no control over the labeling process. While the poison samples are perturbed to achieve the system's misbehavior with regards to specific target inputs, such perturbations are small enough to justify the original labels in the human perception.…”
Section: Introductionmentioning
confidence: 99%
“…To mitigate this limitation, we adopt the Bullseye Polytope attack [1] and extend it as follows: at the beginning of each round of the attack, the surrogate networks are trained on the current version of the (poisoned) dataset. Then, the poisons are changed to achieve the desired heuristics with regards to the refreshed surrogate models.…”
Section: Introductionmentioning
confidence: 99%
See 2 more Smart Citations