{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/exacerbating-algorithmic-bias-through","title":"Exacerbating Algorithmic Bias through Fairness Attacks","arxiv_id":"2012.08723","date":"2020-12-16","proceeding":null,"authors":["Ninareh Mehrabi","Muhammad Naveed","Fred Morstatter","Aram Galstyan"],"abstract":"Algorithmic fairness has attracted significant attention in recent years, with many quantitative measures suggested for characterizing the fairness of different machine learning algorithms. Despite this interest, the robustness of those fairness measures with respect to an intentional adversarial attack has not been properly addressed. Indeed, most adversarial machine learning has focused on the impact of malicious attacks on the accuracy of the system, without any regard to the system's fairness. We propose new types of data poisoning attacks where an adversary intentionally targets the fairness of a system. Specifically, we propose two families of attacks that target fairness measures. In the anchoring attack, we skew the decision boundary by placing poisoned points near specific target points to bias the outcome. In the influence attack on fairness, we aim to maximize the covariance between the sensitive attributes and the decision outcome and affect the fairness of the model. We conduct extensive experiments that indicate the effectiveness of our proposed attacks.","url_abs":"https://arxiv.org/abs/2012.08723v1","url_pdf":"https://arxiv.org/pdf/2012.08723v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"exacerbating-algorithmic-bias-through","repo_url":"https://github.com/Ninarehm/attack","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"tf","reach":null}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"},{"task_slug":"machine-learning","task_name":"BIG-bench Machine Learning"},{"task_slug":"data-poisoning","task_name":"Data Poisoning"},{"task_slug":"fairness","task_name":"Fairness"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2012.08723","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2012.08723"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/Ninarehm/attack","reach":null}],"summary":{"ran_draft_wrong":3},"by_repo_kind":{"official":{"samples":3,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"68ad19597304e430","entry":"get_projection_to_box_around_orig_point","repo":"Ninarehm/attack","repo_kind":"official","path":"Fairness_attack/influence/influence/dataset_poisoning.py","file_url":"https://github.com/Ninarehm/attack/blob/HEAD/Fairness_attack/influence/influence/dataset_poisoning.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"68ad19597304e430"}},{"code_sha256_prefix":"5a433e963babd1cc","entry":"poison_with_influence_proj_gradient_step","repo":"Ninarehm/attack","repo_kind":"official","path":"Fairness_attack/influence/influence/dataset_poisoning.py","file_url":"https://github.com/Ninarehm/attack/blob/HEAD/Fairness_attack/influence/influence/dataset_poisoning.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"5a433e963babd1cc"}},{"code_sha256_prefix":"09fe17271407a870","entry":"select_examples_to_attack","repo":"Ninarehm/attack","repo_kind":"official","path":"Fairness_attack/influence/influence/dataset_poisoning.py","file_url":"https://github.com/Ninarehm/attack/blob/HEAD/Fairness_attack/influence/influence/dataset_poisoning.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"09fe17271407a870"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}