Pith. sign in

REVIEW 4 cited by

Enhancing Robustness of Machine Learning Systems via Data Transformations

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1704.02654 v4 pith:3ULOX6M7 submitted 2017-04-09 cs.CR cs.LG

classification cs.CRcs.LG
keywords datadefensetransformationsattacksclassificationevasionincludingclassifiers
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

We propose the use of data transformations as a defense against evasion attacks on ML classifiers. We present and investigate strategies for incorporating a variety of data transformations including dimensionality reduction via Principal Component Analysis and data `anti-whitening' to enhance the resilience of machine learning, targeting both the classification and the training phase. We empirically evaluate and demonstrate the feasibility of linear transformations of data as a defense mechanism against evasion attacks using multiple real-world datasets. Our key findings are that the defense is (i) effective against the best known evasion attacks from the literature, resulting in a two-fold increase in the resources required by a white-box adversary with knowledge of the defense for a successful attack, (ii) applicable across a range of ML classifiers, including Support Vector Machines and Deep Neural Networks, and (iii) generalizable to multiple application domains, including image classification and human activity classification.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Random Directional Attack for Fooling Deep Neural Networks

    cs.CR 2019-08 conditional novelty 6.0 of 10

    A hill-climbing search over randomly rotated directions generates adversarial examples with success rates competitive with gradient-based attacks, including in black-box settings.

  2. Weak Links in LinkedIn: Enhancing Fake Profile Detection in the Age of LLMs

    cs.SI 2025-07 conditional novelty 5.0 of 10

    GPT-assisted adversarial retraining restores LinkedIn fake-profile detectors from a 42-52 percent false accept rate on AI-written profiles to 1-7 percent.

  3. MetaAdvDet: Towards Robust Detection of Evolving Adversarial Attacks

    cs.CV 2019-08 conditional novelty 5.0 of 10

    MetaAdvDet uses a MAML-style double-network meta-learner to detect evolving adversarial attacks with one to five labeled examples, outperforming non-meta baselines on most tested benchmarks.

  4. On Defending Against Label Flipping Attacks on Malware Detection Systems

    cs.LG 2019-08 reject novelty 4.0 of 10

    A silhouette-clustering label flipping attack and two semi-supervised defenses (LSD, CSD) are proposed, with claimed accuracy gains over KSSD on Android malware datasets, but the CSD algorithm is not implementable as written.

Pith tools