{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/poisoning-attacks-on-algorithmic-fairness","title":"Poisoning Attacks on Algorithmic Fairness","arxiv_id":"2004.07401","date":"2020-04-15","proceeding":null,"authors":["David Solans","Battista Biggio","Carlos Castillo"],"abstract":"Research in adversarial machine learning has shown how the performance of machine learning models can be seriously compromised by injecting even a small fraction of poisoning points into the training data. While the effects on model accuracy of such poisoning attacks have been widely studied, their potential effects on other model performance metrics remain to be evaluated. In this work, we introduce an optimization framework for poisoning attacks against algorithmic fairness, and develop a gradient-based poisoning attack aimed at introducing classification disparities among different groups in the data. We empirically show that our attack is effective not only in the white-box setting, in which the attacker has full access to the target model, but also in a more challenging black-box scenario in which the attacks are optimized against a substitute model and then transferred to the target model. We believe that our findings pave the way towards the definition of an entirely novel set of adversarial attacks targeting algorithmic fairness in different scenarios, and that investigating such vulnerabilities will help design more robust algorithms and countermeasures in the future.","url_abs":"https://arxiv.org/abs/2004.07401v3","url_pdf":"https://arxiv.org/pdf/2004.07401v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"poisoning-attacks-on-algorithmic-fairness","repo_url":"https://github.com/dsolanno/Poisoning-Attacks-on-Algorithmic-Fairness","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"none","reach":null}],"tasks":[{"task_slug":"machine-learning","task_name":"BIG-bench Machine Learning"},{"task_slug":"fairness","task_name":"Fairness"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2004.07401","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2004.07401"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/dsolanno/Poisoning-Attacks-on-Algorithmic-Fairness","reach":null}],"summary":{"ran_fixture":2,"ran_honours":1},"by_repo_kind":{"official":{"samples":3,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"c7b99f612286a736","entry":"calculate_disparate_impact","repo":"dsolanno/Poisoning-Attacks-on-Algorithmic-Fairness","repo_kind":"official","path":"SecML/fairness/utils.py","file_url":"https://github.com/dsolanno/Poisoning-Attacks-on-Algorithmic-Fairness/blob/HEAD/SecML/fairness/utils.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"invariant","behaviour_fingerprint":true,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"c7b99f612286a736"}},{"code_sha256_prefix":"a7116e8371f350b5","entry":"generate_synthetic_data","repo":"dsolanno/Poisoning-Attacks-on-Algorithmic-Fairness","repo_kind":"official","path":"SecML/fairness/utils.py","file_url":"https://github.com/dsolanno/Poisoning-Attacks-on-Algorithmic-Fairness/blob/HEAD/SecML/fairness/utils.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"deterministic","behaviour_fingerprint":true,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"a7116e8371f350b5"}},{"code_sha256_prefix":"6fcf2ca73a64c854","entry":"get_false_positive_rate","repo":"dsolanno/Poisoning-Attacks-on-Algorithmic-Fairness","repo_kind":"official","path":"SecML/fairness/utils.py","file_url":"https://github.com/dsolanno/Poisoning-Attacks-on-Algorithmic-Fairness/blob/HEAD/SecML/fairness/utils.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":"invariant","behaviour_fingerprint":true,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"6fcf2ca73a64c854"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}