Certified and Forensic Defenses against Poisoning and Backdoor Attacks
dc.contributor.advisor | Lowd, Daniel | |
dc.contributor.author | Hammoudeh, Zayd | |
dc.date.accessioned | 2024-03-25T17:22:57Z | |
dc.date.available | 2024-03-25T17:22:57Z | |
dc.date.issued | 2024-03-25 | |
dc.description.abstract | Data poisoning and backdoor attacks manipulate model predictions by inserting malicious instances into the training set. Most existing defenses against poisoning and backdoor attacks are empirical and easily evaded by an adaptive attacker. In addition, existing empirical defenses provide, at best, minimal insights into an attacker's identity, goals, and methods. In contrast, this work proposes two classes of poisoning and backdoor defenses: (1) certified defenses, which provide provable guarantees on their robustness and (2) forensic defenses, which provide actionable, human-interpretable insights into an attack's goals so as to stop the attack via intervention outside the ML system. We focus on certified defenses for regression, where the model predicts a continuous value, and sparse (L0) attacks, where the adversary controls an unknown subset of the training and test features. Our forensic defense identifies the target of poisoning and backdoor attacks while simultaneously mitigating the attack; we validate our forensic defense on a wide range of data modalities, including speech, text, and vision. This dissertation includes previously published and unpublished coauthored material. | en_US |
dc.identifier.uri | https://hdl.handle.net/1794/29279 | |
dc.language.iso | en_US | |
dc.publisher | University of Oregon | |
dc.rights | All Rights Reserved. | |
dc.subject | Adversarial Robustness | en_US |
dc.subject | Backdoor Attack | en_US |
dc.subject | Certified Robustness | en_US |
dc.subject | Data Poisoning | en_US |
dc.subject | Evasion Attack | en_US |
dc.subject | Training Data Attribution | en_US |
dc.title | Certified and Forensic Defenses against Poisoning and Backdoor Attacks | |
dc.type | Electronic Thesis or Dissertation | |
thesis.degree.discipline | Department of Computer Science | |
thesis.degree.grantor | University of Oregon | |
thesis.degree.level | doctoral | |
thesis.degree.name | Ph.D. |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- Hammoudeh_oregon_0171A_13742.pdf
- Size:
- 2.13 MB
- Format:
- Adobe Portable Document Format