English

Poisons that are learned faster are more effective

Machine Learning 2022-04-20 v1 Cryptography and Security

Abstract

Imperceptible poisoning attacks on entire datasets have recently been touted as methods for protecting data privacy. However, among a number of defenses preventing the practical use of these techniques, early-stopping stands out as a simple, yet effective defense. To gauge poisons' vulnerability to early-stopping, we benchmark error-minimizing, error-maximizing, and synthetic poisons in terms of peak test accuracy over 100 epochs and make a number of surprising observations. First, we find that poisons that reach a low training loss faster have lower peak test accuracy. Second, we find that a current state-of-the-art error-maximizing poison is 7 times less effective when poison training is stopped at epoch 8. Third, we find that stronger, more transferable adversarial attacks do not make stronger poisons. We advocate for evaluating poisons in terms of peak test accuracy.

Keywords

Cite

@article{arxiv.2204.08615,
  title  = {Poisons that are learned faster are more effective},
  author = {Pedro Sandoval-Segura and Vasu Singla and Liam Fowl and Jonas Geiping and Micah Goldblum and David Jacobs and Tom Goldstein},
  journal= {arXiv preprint arXiv:2204.08615},
  year   = {2022}
}

Comments

8 pages, 4 figures. Accepted to CVPR 2022 Art of Robustness Workshop

R2 v1 2026-06-24T10:51:36.817Z