{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/detection-of-adversarial-training-examples-in","title":"Detection of Adversarial Training Examples in Poisoning Attacks through Anomaly Detection","arxiv_id":"1802.03041","date":"2018-02-08","proceeding":null,"authors":["Andrea Paudice","Luis Muñoz-González","Andras Gyorgy","Emil C. Lupu"],"abstract":"Machine learning has become an important component for many systems and\napplications including computer vision, spam filtering, malware and network\nintrusion detection, among others. Despite the capabilities of machine learning\nalgorithms to extract valuable information from data and produce accurate\npredictions, it has been shown that these algorithms are vulnerable to attacks.\nData poisoning is one of the most relevant security threats against machine\nlearning systems, where attackers can subvert the learning process by injecting\nmalicious samples in the training data. Recent work in adversarial machine\nlearning has shown that the so-called optimal attack strategies can\nsuccessfully poison linear classifiers, degrading the performance of the system\ndramatically after compromising a small fraction of the training dataset. In\nthis paper we propose a defence mechanism to mitigate the effect of these\noptimal poisoning attacks based on outlier detection. We show empirically that\nthe adversarial examples generated by these attack strategies are quite\ndifferent from genuine points, as no detectability constrains are considered to\ncraft the attack. Hence, they can be detected with an appropriate pre-filtering\nof the training dataset.","url_abs":"http://arxiv.org/abs/1802.03041v1","url_pdf":"http://arxiv.org/pdf/1802.03041v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"detection-of-adversarial-training-examples-in","repo_url":"https://github.com/lmunoz-gonzalez/Poisoning-Attacks-with-Back-gradient-Optimization","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"none","reach":{"status":"ok","spdx":"MIT"}}],"tasks":[{"task_slug":"anomaly-detection","task_name":"Anomaly Detection"},{"task_slug":"machine-learning","task_name":"BIG-bench Machine Learning"},{"task_slug":"data-poisoning","task_name":"Data Poisoning"},{"task_slug":"intrusion-detection","task_name":"Intrusion Detection"},{"task_slug":"network-intrusion-detection","task_name":"Network Intrusion Detection"},{"task_slug":"outlier-detection","task_name":"Outlier Detection"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/1802.03041","atlas_url":"https://app.syntology.ai/?focus=1802.03041","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}