arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.25681cs.LGcs.CRcs.SYeess.SY

隐蔽攻击下线性模型的对抗训练

Adversarial Training of Linear Models under Stealthy Attacks

Lovisa Eriksson, Dave Zachariah, André M. H. Teixeira

首次发表
浏览论文内容

中文总结 AI 辅助

针对线性模型易受隐蔽攻击的问题,提出基于检测器的切换模型,推导对抗风险凸公式,经数值模拟验证其在部分受攻击数据上性能更优。

中文摘要 AI 辅助

预测模型广泛应用于诸多领域,但易受虚假数据注入攻击。为解决该问题,已提出检测方案与对抗训练方法,但此类方法缺乏抵御隐蔽攻击的保证。因此,我们提出一种基于检测器的切换模型,其中最优攻击策略具有隐蔽性。针对线性预测模型,我们推导了所得对抗风险的凸公式,该模型纳入受保护特征并引入超参数对攻击概率建模,可实现干净数据与受攻击数据场景间的显式性能权衡。在真实数据与合成数据上进行的数值模拟表明,即便攻击概率设定有误,模型在部分受攻击数据上仍表现出更优性能。

英文摘要

Predictive models are widely used in many fields, but are vulnerable to false data injection attacks. To address this, detection schemes and adversarial training have been proposed, but such approaches lack guarantees against stealthy attacks. We therefore propose a detector-based switched model, in which optimal attack strategies are stealthy. For linear prediction models, we derive a convex formulation of the resulting adversarial risk. The model incorporates protected features and introduces a hyperparameter modelling attack probability, enabling an explicit performance trade-off between clean and attacked data regimes. Numerical simulations on real and synthetic data show improved performance on partially attacked data, even for misspecified attack probabilities.

发表机构

  • Uppsala University(乌普萨拉大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑