conference-paper Open access

Symmetric adversarial poisoning against deep learning

Research footprint

At a glance

Citations
0
References
51
Comments
0
Paper overview

Abstract

Data poisoning is known as the goal of finding small modifications of training data which make them not suitable anymore for training a targeted model.Recently, an efficient symmetric poisoning attack targeting frozen deep features plus support vector machine has been found. However, new experiments presented in this paper shows that this attack is not symmetric anymore on unfrozen/real deep networks.Then, several extensions of this attack are considered on CIFAR10/CIFAR100 with both VGG and ResNet backbone leading to a symmetric attack. On VGG/CIFAR10 setting, this extended attack makes performances moving by -60%,+5% from native accuracy using perturbations invisible to human eyes. Code is available at github.com/achanhon/AdversarialModel.

Record transparency

Publication details

DOI
10.1109/ipta50016.2020.9286651
OpenAlex
W3112743260
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.