Adequacy of the Gradient-Descent Method for Classifier Evasion Attacks

04/06/2017
by   Yi Han, et al.
0

Despite the wide use of machine learning in adversarial settings including computer security, recent studies have demonstrated vulnerabilities to evasion attacks---carefully crafted adversarial samples that closely resemble legitimate instances, but cause misclassification. In this paper, we examine the adequacy of the leading approach to generating adversarial samples---the gradient descent approach. In particular (1) we perform extensive experiments on three datasets, MNIST, USPS and Spambase, in order to analyse the effectiveness of the gradient-descent method against non-linear support vector machines, and conclude that carefully reduced kernel smoothness can significantly increase robustness to the attack; (2) we demonstrate that separated inter-class support vectors lead to more secure models, and propose a quantity similar to margin that can efficiently predict potential susceptibility to gradient-descent attacks, before the attack is launched; and (3) we design a new adversarial sample construction algorithm based on optimising the multiplicative ratio of class decision functions.

READ FULL TEXT

page 1

page 3

research
07/03/2018

On the Computational Power of Online Gradient Descent

We prove that the evolution of weight vectors in online gradient descent...
research
06/01/2022

Support Vector Machines under Adversarial Label Contamination

Machine learning algorithms are increasingly being applied in security-r...
research
06/27/2012

Poisoning Attacks against Support Vector Machines

We investigate a family of poisoning attacks against Support Vector Mach...
research
12/06/2018

Max-Margin Adversarial (MMA) Training: Direct Input Space Margin Maximization through Adversarial Training

We propose Max-Margin Adversarial (MMA) training for directly maximizing...
research
05/20/2019

Adaptive DDoS attack detection method based on multiple-kernel learning

Distributed denial of service (DDoS) attacks have caused huge economic l...
research
01/31/2023

Robust Linear Regression: Gradient-descent, Early-stopping, and Beyond

In this work we study the robustness to adversarial attacks, of early-st...
research
11/08/2021

Gradient-Descent for Randomized Controllers under Partial Observability

Randomization is a powerful technique to create robust controllers, in p...

Please sign up or login with your details

Forgot password? Click here to reset