Mole Recruitment: Poisoning of Image Classifiers via Selective Batch Sampling

03/30/2023
by   Ethan Wisdom, et al.
0

In this work, we present a data poisoning attack that confounds machine learning models without any manipulation of the image or label. This is achieved by simply leveraging the most confounding natural samples found within the training data itself, in a new form of a targeted attack coined "Mole Recruitment." We define moles as the training samples of a class that appear most similar to samples of another class, and show that simply restructuring training batches with an optimal number of moles can lead to significant degradation in the performance of the targeted class. We show the efficacy of this novel attack in an offline setting across several standard image classification datasets, and demonstrate the real-world viability of this attack in a continual learning (CL) setting. Our analysis reveals that state-of-the-art models are susceptible to Mole Recruitment, thereby exposing a previously undetected vulnerability of image classifiers.

READ FULL TEXT

page 3

page 12

page 15

research
11/29/2022

Training Time Adversarial Attack Aiming the Vulnerability of Continual Learning

Generally, regularization-based continual learning models limit access t...
research
02/16/2021

Adversarial Targeted Forgetting in Regularization and Generative Based Continual Learning Models

Continual (or "incremental") learning approaches are employed when addit...
research
02/11/2022

Exemplar-free Online Continual Learning

Targeted for real world scenarios, online continual learning aims to lea...
research
11/03/2021

A Meta-Learned Neuron model for Continual Learning

Continual learning is the ability to acquire new knowledge without forge...
research
02/09/2022

False Memory Formation in Continual Learners Through Imperceptible Backdoor Trigger

In this brief, we show that sequentially learning new information presen...
research
05/02/2023

Prompt as Triggers for Backdoor Attack: Examining the Vulnerability in Language Models

The prompt-based learning paradigm, which bridges the gap between pre-tr...
research
04/27/2020

Printing and Scanning Attack for Image Counter Forensics

Examining the authenticity of images has become increasingly important a...

Please sign up or login with your details

Forgot password? Click here to reset