在线AutoML:评估物联网网络中对抗训练防御策略的投毒攻击
Online AutoML: Evaluating Poisoning Attacks on Adversarial Training Defense Strategy in IoT Networks
查看机构详情
- Ontario Tech University(安大略理工大学)
- Alex Ekwueme Federal University(亚历克斯·埃克武梅联邦大学)
机构由 AI 辅助整理,请以论文原文为准。
浏览论文内容
中文总结 AI 辅助
本研究通过在线AutoML管道评估对抗训练防御在物联网流式数据中应对投毒攻击(标签翻转和噪声注入)的有效性,发现AT-SRP和AT-LB分别在两类攻击下取得最佳F1分数。
中文摘要 AI 辅助
机器学习(ML)驱动的投毒攻击向量是一种对抗性操作,攻击者故意插入、破坏或篡改训练数据,以扭曲机器学习模型的学习过程。其目标是降低模型效能、植入偏见、诱发错误分类,或包含可能在实施过程中被攻击的隐蔽后门。在流式环境中,投毒攻击构成重大风险,因为模型会基于不断流入的数据持续更新。攻击者可能逐步将有害样本引入该数据流,导致模型随时间同化错误特征而未被及时发现。因此,本研究旨在通过用于物联网(IoT)网络的在线AutoML管道,评估对抗训练(AT)防御方法针对投毒攻击(标签翻转和噪声注入)的有效性。具体而言,将投毒攻击(标签翻转和噪声注入)应用于支持流式处理的AutoML学习器(Hoeffding树(HT)、Leveraging Bagging(LB)、自适应随机森林(ARF)、Hoeffding自适应树(HAT)和流式随机补丁(SRP))。在最强投毒率(PR=1.0)下,AT-SRP在标签翻转投毒攻击下取得了最高的F1分数(0.904),而AT-LB在噪声注入投毒攻击下取得了最高的F1分数(0.933)。最后,使用了多种漂移检测方法进行滚动准确率和前序评估。
英文摘要
Machine learning (ML)-powered poisoning attack vectors are adversarial maneuvers whereby an attacker intentionally inserts, corrupts, or alters training data to distort an ML model's learning process. The objective is to diminish model efficacy, instill biases, induce misclassifications, or include concealed backdoors that may be attacked during implementation. In streaming contexts, poisoning attacks pose significant risks since models perpetually update based on incoming streams of data. An assailant may incrementally introduce harmful samples into this data stream, leading the model to assimilate erroneous features over time without timely identification. Therefore, this study is aimed at evaluating the efficacy of the adversarial training (AT) defense approach against poisoning attacks (label flip and noise injection) using an online AutoML pipeline for Internet of Things (IoT) networks. Specifically, poisoning attacks (label flip and noise injection) were applied to streaming-capable AutoML learners (Hoeffding Tree (HT), Leveraging Bagging (LB), Adaptive Random Forest (ARF), Hoeffding Adaptive Tree (HAT), and Streaming Random Patches (SRP)). Under the strongest poisoning rate (PR = 1.0), AT-SRP achieved the highest F1-score against label flip poisoning (0.904), while AT-LB achieved the highest F1-score against noise-injection poisoning (0.933). Finally, several drift detection methods were used for rolling accuracy and prequential evaluation.