{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/poisoning-attacks-against-support-vector","title":"Poisoning Attacks against Support Vector Machines","arxiv_id":"1206.6389","date":"2012-06-27","proceeding":null,"authors":["Battista Biggio","Blaine Nelson","Pavel Laskov"],"abstract":"We investigate a family of poisoning attacks against Support Vector Machines\n(SVM). Such attacks inject specially crafted training data that increases the\nSVM's test error. Central to the motivation for these attacks is the fact that\nmost learning algorithms assume that their training data comes from a natural\nor well-behaved distribution. However, this assumption does not generally hold\nin security-sensitive settings. As we demonstrate, an intelligent adversary\ncan, to some extent, predict the change of the SVM's decision function due to\nmalicious input and use this ability to construct malicious data. The proposed\nattack uses a gradient ascent strategy in which the gradient is computed based\non properties of the SVM's optimal solution. This method can be kernelized and\nenables the attack to be constructed in the input space even for non-linear\nkernels. We experimentally demonstrate that our gradient ascent procedure\nreliably identifies good local maxima of the non-convex validation error\nsurface, which significantly increases the classifier's test error.","url_abs":"http://arxiv.org/abs/1206.6389v3","url_pdf":"http://arxiv.org/pdf/1206.6389v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"poisoning-attacks-against-support-vector","repo_url":"https://github.com/Koukyosyumei/AIJack","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":"https://app.syntology.ai/?focus=1206.6389","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}