Provably effective detection of effective data poisoning attacks
Cryptography and Security
2025-01-22 v1 Computer Vision and Pattern Recognition
Machine Learning
Machine Learning
Abstract
This paper establishes a mathematically precise definition of dataset poisoning attack and proves that the very act of effectively poisoning a dataset ensures that the attack can be effectively detected. On top of a mathematical guarantee that dataset poisoning is identifiable by a new statistical test that we call the Conformal Separability Test, we provide experimental evidence that we can adequately detect poisoning attempts in the real world.
Keywords
Cite
@article{arxiv.2501.11795,
title = {Provably effective detection of effective data poisoning attacks},
author = {Jonathan Gallagher and Yasaman Esfandiari and Callen MacPhee and Michael Warren},
journal= {arXiv preprint arXiv:2501.11795},
year = {2025}
}