发表机构
Minot State University(迈诺特州立大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究在MNIST和Fashion-MNIST上实证评估标签翻转与后门投毒攻击,发现后门攻击隐蔽且成功率高,需安全导向评估。
AI 中文摘要
数据投毒通过破坏训练数据来降低模型性能或植入攻击者控制的行为。本研究在MNIST和Fashion-MNIST数据集上,使用三种基线分类器(逻辑回归、线性SVM和随机森林)评估了两种具有代表性的训练时攻击:标签翻转和后门投毒。将干净训练与5%、10%和20%的投毒率进行比较,评估指标包括干净测试准确率、宏平均精确率、宏平均召回率、宏平均F1分数,以及针对后门攻击的攻击成功率。标签翻转导致明显的性能下降,其中逻辑回归和线性SVM受影响最大,而随机森林保持相对稳定。后门投毒在两个数据集和所有三个模型上均达到了0.9667至1.0000的攻击成功率,同时通常保持接近基线的干净测试性能。结果将无差别投毒(可在标准指标中显现)与针对性后门投毒(在嵌入高度有效的恶意行为的同时保持相对隐蔽)区分开来,并支持超越传统干净测试指标的安全导向评估。
英文摘要
Data poisoning corrupts training data to degrade a model or to plant attacker-controlled behavior. This study evaluates two representative training-time attacks, label flipping and backdoor poisoning, on MNIST and Fashion-MNIST with three baseline classifiers: Logistic Regression, Linear SVM, and Random Forest. Clean training is compared with poisoning rates of 5%, 10%, and 20% using clean-test accuracy, macro-precision, macro-recall, macro-F1, and, for backdoors, attack success rate. Label flipping caused clear degradation, largest for Logistic Regression and Linear SVM, while Random Forest stayed comparatively stable. Backdoor poisoning reached attack success rates from 0.9667 to 1.0000 on both datasets and all three models while often keeping clean-test performance near baseline. The results separate indiscriminate poisoning, which shows up in standard metrics, from targeted backdoor poisoning, which stays comparatively stealthy while embedding highly effective malicious behavior, and they support security-oriented evaluation beyond conventional clean-test metrics.
CommentsPresented at the 58th Midwest Instruction and Computing Symposium (MICS 2026), Eau Claire, WI, March 27 to 28, 2026. 15 pages, 4 figures, 3 tables