English

Provably effective detection of effective data poisoning attacks

Cryptography and Security 2025-01-22 v1 Computer Vision and Pattern Recognition Machine Learning Machine Learning

Abstract

This paper establishes a mathematically precise definition of dataset poisoning attack and proves that the very act of effectively poisoning a dataset ensures that the attack can be effectively detected. On top of a mathematical guarantee that dataset poisoning is identifiable by a new statistical test that we call the Conformal Separability Test, we provide experimental evidence that we can adequately detect poisoning attempts in the real world.

Keywords

Cite

@article{arxiv.2501.11795,
  title  = {Provably effective detection of effective data poisoning attacks},
  author = {Jonathan Gallagher and Yasaman Esfandiari and Callen MacPhee and Michael Warren},
  journal= {arXiv preprint arXiv:2501.11795},
  year   = {2025}
}
R2 v1 2026-06-28T21:11:53.357Z