Periodic Recovery From Poisoning Attacks in Machine Learning
At a glance
- Citations
- 0
- References
- 25
- Comments
- 0
Abstract
Recovery from poisoning attacks aims to eliminate the influence of a given set of deleted poisoned training data on a model. In practice, model recovery often happensperiodicallysince data deletion occurs repeatedly after a model has been trained. Existing efficient model recovery methods are designed forsingle-shotmodel recovery. When applied to periodic model recovery, they treat the instances of recovery independently, leading to a large total overhead over time. In this work, we propose PeriRecover, an efficient periodic model recovery method. Our key idea is to extract some common information during the original model training, which can be used to accelerate all instances of model recovery. In particular, we propose to compute and store the diagonals of the Hessian matrix of the loss function during the original model training. Given such information, each instance of model recovery can efficiently estimate the gradients to update the model instead of exactly computing them. Theoretically, we show that the model recovered by PeriRecover is close to the one recovered by training-from-scratch under some assumptions, achievingcertified recovery. Empirically, we apply PeriRecover to supervised learning and recommender systems, and we consider targeted attacks and untargeted attacks. Our results show that PeriRecover is much more efficient and/or accurate than existing model recovery methods.
Publication details
- DOI
- 10.1109/tdsc.2025.3560239
- OpenAlex
- W4409355989
- Document type
- article
- Language
- EN
- Source
- IEEE Transactions on Dependable and Secure Computing
- Last metadata update
Comments
Log in to join the discussion.