{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/manipulating-machine-learning-poisoning","title":"Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression Learning","arxiv_id":"1804.00308","date":"2018-04-01","proceeding":null,"authors":["Matthew Jagielski","Alina Oprea","Battista Biggio","Chang Liu","Cristina Nita-Rotaru","Bo Li"],"abstract":"As machine learning becomes widely used for automated decisions, attackers have strong incentives to manipulate the results and models generated by machine learning algorithms. In this paper, we perform the first systematic study of poisoning attacks and their countermeasures for linear regression models. In poisoning attacks, attackers deliberately influence the training data to manipulate the results of a predictive model. We propose a theoretically-grounded optimization framework specifically designed for linear regression and demonstrate its effectiveness on a range of datasets and models. We also introduce a fast statistical attack that requires limited knowledge of the training process. Finally, we design a new principled defense method that is highly resilient against all poisoning attacks. We provide formal guarantees about its convergence and an upper bound on the effect of poisoning attacks when the defense is deployed. We evaluate extensively our attacks and defenses on three realistic datasets from health care, loan assessment, and real estate domains.","url_abs":"https://arxiv.org/abs/1804.00308v3","url_pdf":"https://arxiv.org/pdf/1804.00308v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"manipulating-machine-learning-poisoning","repo_url":"https://github.com/jagielski/manip-ml","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"none","reach":{"status":"ok","spdx":"MIT"}}],"tasks":[{"task_slug":"machine-learning","task_name":"BIG-bench Machine Learning"},{"task_slug":"regression-1","task_name":"regression"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1804.00308","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1804.00308"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/jagielski/manip-ml","reach":{"status":"ok","spdx":"MIT"}}],"summary":{"unverified":6},"by_repo_kind":{"official":{"samples":6,"ran":0,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"0e187ca6739c713f","entry":"huberreg","repo":"jagielski/manip-ml","repo_kind":"official","path":"defense/defenses.py","file_url":"https://github.com/jagielski/manip-ml/blob/HEAD/defense/defenses.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"0e187ca6739c713f"}},{"code_sha256_prefix":"b94bf19ddac62f7a","entry":"open_dataset","repo":"jagielski/manip-ml","repo_kind":"official","path":"poisoning/poison.py","file_url":"https://github.com/jagielski/manip-ml/blob/HEAD/poisoning/poison.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"b94bf19ddac62f7a"}},{"code_sha256_prefix":"1570d1a81cbced19","entry":"ransacmodel","repo":"jagielski/manip-ml","repo_kind":"official","path":"defense/defenses.py","file_url":"https://github.com/jagielski/manip-ml/blob/HEAD/defense/defenses.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"1570d1a81cbced19"}},{"code_sha256_prefix":"4060a2063c82a322","entry":"read_dataset_file","repo":"jagielski/manip-ml","repo_kind":"official","path":"poisoning/poison.py","file_url":"https://github.com/jagielski/manip-ml/blob/HEAD/poisoning/poison.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"4060a2063c82a322"}},{"code_sha256_prefix":"20526eed4a28bbd4","entry":"robustopt","repo":"jagielski/manip-ml","repo_kind":"official","path":"poisoning/poison.py","file_url":"https://github.com/jagielski/manip-ml/blob/HEAD/poisoning/poison.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"20526eed4a28bbd4"}},{"code_sha256_prefix":"4f35fd2b96fdf144","entry":"trimclf","repo":"jagielski/manip-ml","repo_kind":"official","path":"defense/defenses.py","file_url":"https://github.com/jagielski/manip-ml/blob/HEAD/defense/defenses.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"4f35fd2b96fdf144"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}