Pith. sign in

REVIEW 2 cited by

Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1804.00308 v3 pith:5BZJTRWK submitted 2018-04-01 cs.CR cs.GTcs.LG

classification cs.CRcs.GTcs.LG
keywords attackspoisoninglearningmachinemodelsregressionattackerscountermeasures
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

As machine learning becomes widely used for automated decisions, attackers have strong incentives to manipulate the results and models generated by machine learning algorithms. In this paper, we perform the first systematic study of poisoning attacks and their countermeasures for linear regression models. In poisoning attacks, attackers deliberately influence the training data to manipulate the results of a predictive model. We propose a theoretically-grounded optimization framework specifically designed for linear regression and demonstrate its effectiveness on a range of datasets and models. We also introduce a fast statistical attack that requires limited knowledge of the training process. Finally, we design a new principled defense method that is highly resilient against all poisoning attacks. We provide formal guarantees about its convergence and an upper bound on the effect of poisoning attacks when the defense is deployed. We evaluate extensively our attacks and defenses on three realistic datasets from health care, loan assessment, and real estate domains.

Discussion (0). Sign in to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Structural Adversarial Attacks on Relational Deep Learning under Integrity Constraints

    cs.LG 2026-07 conditional novelty 6.0 of 10

    Gradient-guided rewiring of foreign-key edges in relational databases degrades GNN predictions on regression tasks while preserving schema integrity constraints.

  2. Algorithmic Complexity Attacks on All Learned Cardinality Estimators: A Data-centric Approach

    cs.DB 2025-07 conditional novelty 6.0 of 10

    A black-box data-poisoning attack on learned cardinality estimators: altering under 1% of training tuples degrades six estimators by up to three orders of magnitude, and finding the optimal poisoning strategy is NP-hard.

Pith tools