{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/game-theoretic-unlearnable-example-generator","title":"Game-Theoretic Unlearnable Example Generator","arxiv_id":"2401.17523","date":"2024-01-31","proceeding":null,"authors":["Shuang Liu","Yihan Wang","Xiao-Shan Gao"],"abstract":"Unlearnable example attacks are data poisoning attacks aiming to degrade the clean test accuracy of deep learning by adding imperceptible perturbations to the training samples, which can be formulated as a bi-level optimization problem. However, directly solving this optimization problem is intractable for deep neural networks. In this paper, we investigate unlearnable example attacks from a game-theoretic perspective, by formulating the attack as a nonzero sum Stackelberg game. First, the existence of game equilibria is proved under the normal setting and the adversarial training setting. It is shown that the game equilibrium gives the most powerful poison attack in that the victim has the lowest test accuracy among all networks within the same hypothesis space, when certain loss functions are used. Second, we propose a novel attack method, called the Game Unlearnable Example (GUE), which has three main gradients. (1) The poisons are obtained by directly solving the equilibrium of the Stackelberg game with a first-order algorithm. (2) We employ an autoencoder-like generative network model as the poison attacker. (3) A novel payoff function is introduced to evaluate the performance of the poison. Comprehensive experiments demonstrate that GUE can effectively poison the model in various scenarios. Furthermore, the GUE still works by using a relatively small percentage of the training data to train the generator, and the poison generator can generalize to unseen data well. Our implementation code can be found at https://github.com/hong-xian/gue.","url_abs":"https://arxiv.org/abs/2401.17523v1","url_pdf":"https://arxiv.org/pdf/2401.17523v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"game-theoretic-unlearnable-example-generator","repo_url":"https://github.com/hong-xian/gue","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"data-poisoning","task_name":"Data Poisoning"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2401.17523","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2401.17523"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"deterministic:regex_extraction","url":"https://github.com/hong-xian/gue","reach":null}],"summary":{"ran":5,"ran_draft_wrong":2,"unverified":1},"by_repo_kind":{"official":{"samples":8,"ran":7,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":8,"samples":[{"code_sha256_prefix":"1c2bb8bacd5c71a1","entry":"ResNet","repo":"hong-xian/gue","repo_kind":"official","path":"gue.py","file_url":"https://github.com/hong-xian/gue/blob/HEAD/gue.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":"invariant","behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"1c2bb8bacd5c71a1"}},{"code_sha256_prefix":"f6362fad9eb59b64","entry":"ResNet18","repo":"hong-xian/gue","repo_kind":"official","path":"gue.py","file_url":"https://github.com/hong-xian/gue/blob/HEAD/gue.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"f6362fad9eb59b64"}},{"code_sha256_prefix":"931ee4a531e00798","entry":"create_net","repo":"hong-xian/gue","repo_kind":"official","path":"gue.py","file_url":"https://github.com/hong-xian/gue/blob/HEAD/gue.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"931ee4a531e00798"}},{"code_sha256_prefix":"2cd493567e71bb78","entry":"f","repo":"hong-xian/gue","repo_kind":"official","path":"gue.py","file_url":"https://github.com/hong-xian/gue/blob/HEAD/gue.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"2cd493567e71bb78"}},{"code_sha256_prefix":"d029dd9f6731ca43","entry":"f_theta","repo":"hong-xian/gue","repo_kind":"official","path":"gue.py","file_url":"https://github.com/hong-xian/gue/blob/HEAD/gue.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"d029dd9f6731ca43"}},{"code_sha256_prefix":"f38767d36eae77a4","entry":"g","repo":"hong-xian/gue","repo_kind":"official","path":"gue.py","file_url":"https://github.com/hong-xian/gue/blob/HEAD/gue.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"f38767d36eae77a4"}},{"code_sha256_prefix":"c79c2bb39de6cf5f","entry":"q_a_theta","repo":"hong-xian/gue","repo_kind":"official","path":"gue.py","file_url":"https://github.com/hong-xian/gue/blob/HEAD/gue.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"c79c2bb39de6cf5f"}},{"code_sha256_prefix":"ad233e253082b05d","entry":"bome","repo":"hong-xian/gue","repo_kind":"official","path":"gue.py","file_url":"https://github.com/hong-xian/gue/blob/HEAD/gue.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"ad233e253082b05d"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}