Resilience of Pruned Neural Network Against Poisoning Attack

被引:0
|
作者
Zhao, Bingyin [1 ]
Lao, Yingjie [1 ]
机构
[1] Clemson Univ, Dept Elect & Comp Engn, Clemson, SC 29634 USA
来源
PROCEEDINGS OF THE 2018 13TH INTERNATIONAL CONFERENCE ON MALICIOUS AND UNWANTED SOFTWARE (MALWARE 2018) | 2018年
关键词
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
In the past several years, machine learning, especially deep learning, has achieved remarkable success in various fields. However, it has been shown recently that machine learning algorithms are vulnerable to well crafted attacks. For instance, poisoning attack is effective in manipulating the results of a predictive model by deliberately contaminating the training data. In this paper, we investigate the implication of network pruning on the resilience against poisoning attacks. Our experimental results show that pruning can effectively increase the difficulty of poisoning attack, possibly due to the reduced degrees of freedom in the pruned network. For example, in order to degrade the test accuracy below 60% for the MNIST-1.-7 dataset, only less than 10 retraining epochs with poisoning data are needed for the original network, while about 16 and 40 epochs are required for the 90% and 99% pruned networks, respectively.
引用
收藏
页码:78 / 83
页数:6
相关论文
共 50 条
  • [41] Data Poisoning Attack against Knowledge Graph Embedding
    Zhang, Hengtong
    Zheng, Tianhang
    Gao, Jing
    Miao, Chenglin
    Su, Lu
    Li, Yaliang
    Ren, Kui
    PROCEEDINGS OF THE TWENTY-EIGHTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2019, : 4853 - 4859
  • [42] A pruned feed-forward neural network (pruned-FNN) approach to measure air pollution exposure
    Xi Gong
    Lin Liu
    Yanhong Huang
    Bin Zou
    Yeran Sun
    Li Luo
    Yan Lin
    Environmental Monitoring and Assessment, 2023, 195
  • [43] A pruned feed-forward neural network (pruned-FNN) approach to measure air pollution exposure
    Gong, Xi
    Liu, Lin
    Huang, Yanhong
    Zou, Bin
    Sun, Yeran
    Luo, Li
    Lin, Yan
    ENVIRONMENTAL MONITORING AND ASSESSMENT, 2023, 195 (10)
  • [44] VIKING: Adversarial Attack on Network Embeddings via Supervised Network Poisoning
    Gupta, Viresh
    Chakraborty, Tanmoy
    ADVANCES IN KNOWLEDGE DISCOVERY AND DATA MINING, PAKDD 2021, PT III, 2021, 12714 : 103 - 115
  • [45] Topological Resilience of Complex Networks against Failure and Attack
    Hu, Ziping
    Verma, Pramode K.
    2011 IEEE 5TH INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATION SYSTEMS (ANTS), 2011,
  • [46] INVESTIGATION OF DATA MINING USING PRUNED ARTIFICIAL NEURAL NETWORK TREE
    Kalaiarasi, S. M. A.
    Sainarayanan, G.
    Chekima, Ali
    Teo, Jason
    JOURNAL OF ENGINEERING SCIENCE AND TECHNOLOGY, 2008, 3 (03) : 243 - 255
  • [47] Diagnosis Of Lung Cancer Using Pruned Fuzzy MinMax Neural Network
    Deshmukh, Shraddha
    Shinde, Swati
    2016 INTERNATIONAL CONFERENCE ON AUTOMATIC CONTROL AND DYNAMIC OPTIMIZATION TECHNIQUES (ICACDOT), 2016, : 398 - 402
  • [48] IPRemover: A Generative Model Inversion Attack against Deep Neural Network Fingerprinting and Watermarking
    Zong, Wei
    Chow, Yang-Wai
    Susilo, Willy
    Baek, Joonsang
    Kim, Jongkil
    Camtepe, Seyit
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 7, 2024, : 7837 - 7845
  • [49] Implementation of Pruned Backpropagation Neural Network Based on Photonic Integrated Circuits
    Zhang, Qi
    Xing, Zhuangzhuang
    Huang, Duan
    PHOTONICS, 2021, 8 (09)
  • [50] Backdoor Attack Against Split Neural Network-Based Vertical Federated Learning
    He, Ying
    Shen, Zhili
    Hua, Jingyu
    Dong, Qixuan
    Niu, Jiacheng
    Tong, Wei
    Huang, Xu
    Li, Chen
    Zhong, Sheng
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 748 - 763