{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/108638"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/108638","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Provable stability defenses for targeted data poisoning","abstract":"Modern machine learning systems are often trained on massive, crowdsourced datasets. Due to the impossibility of checking this data, these systems may be susceptible to data poisoning attacks where malicious users inject false training data in order to influence the learned model. While recent work has focused primarily on the untargeted case, where the attacker's goal is to increase overall error, much less is understood about the theoretical underpinnings of targeted data poisoning attacks. These attacks try to cause the learned model to change its prediction on only a few targeted examples without raising suspicion. We suggest algorithmic stability as a sufficient condition for robustness against data poisoning, construct upper bounds on the possible effectiveness of data poisoning attacks against stable algorithms, and propose an algorithm that provides resilience against popular classes of attacks. Empirically, we report findings on the MNIST 1-7 image classification dataset and the TREC 2007 spam detection dataset that confirms our theoretical findings.","abstract_html":"Modern machine learning systems are often trained on massive, crowdsourced datasets. Due to the impossibility of checking this data, these systems may be susceptible to data poisoning attacks where malicious users inject false training data in order to influence the learned model. While recent work has focused primarily on the untargeted case, where the attacker&#x27;s goal is to increase overall error, much less is understood about the theoretical underpinnings of targeted data poisoning attacks. These attacks try to cause the learned model to change its prediction on only a few targeted examples without raising suspicion. We suggest algorithmic stability as a sufficient condition for robustness against data poisoning, construct upper bounds on the possible effectiveness of data poisoning attacks against stable algorithms, and propose an algorithm that provides resilience against popular classes of attacks. Empirically, we report findings on the MNIST 1-7 image classification dataset and the TREC 2007 spam detection dataset that confirms our theoretical findings.","abstract_has_math":false,"creators":["Vijitbenjaronk, Warut D."],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Koyejo, Oluwasanmi"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2020,"date_issued":"2020-10-07T22:44:46Z","date_published":"2020-10-07T22:44:46Z","updated_at":"2026-07-22T22:24:48Z","subjects":["data poisoning","machine learning","robust machine learning","stable support vector machine","algorithmic stability","uniform stability","adversarial machine learning"],"languages":["en"],"rights":["Copyright 2020 Warut D. Vijitbenjaronk"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/108638","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Koyejo, Oluwasanmi"]},{"key":"dc:creator","label":"Author","values":["Vijitbenjaronk, Warut D."]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2020-10-07T22:44:46Z","2020-07-22","2020-08"]},{"key":"dc:type","label":"Dc Type","values":["text","Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["data poisoning","machine learning","robust machine learning","stable support vector machine","algorithmic stability","uniform stability","adversarial machine learning"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2020 Warut D. Vijitbenjaronk"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/108638"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Modern machine learning systems are often trained on massive, crowdsourced datasets. Due to the impossibility of checking this data, these systems may be susceptible to data poisoning attacks where malicious users inject false training data in order to influence the learned model. While recent work has focused primarily on the untargeted case, where the attacker's goal is to increase overall error, much less is understood about the theoretical underpinnings of targeted data poisoning attacks. These attacks try to cause the learned model to change its prediction on only a few targeted examples without raising suspicion. We suggest algorithmic stability as a sufficient condition for robustness against data poisoning, construct upper bounds on the possible effectiveness of data poisoning attacks against stable algorithms, and propose an algorithm that provides resilience against popular classes of attacks. Empirically, we report findings on the MNIST 1-7 image classification dataset and the TREC 2007 spam detection dataset that confirms our theoretical findings.","Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2022-08-01","The student, Warut Vijitbenjaronk, accepted the attached license on 2020-07-21 at 21:20.","The student, Warut Vijitbenjaronk, submitted this Thesis for approval on 2020-07-21 at 21:27.","This Thesis was approved for publication on 2020-07-22 at 11:00.","DSpace SAF Submission Ingestion Package generated from Vireo submission #15718 on 2020-10-02 at 15:34:06","Made available in DSpace on 2020-10-07T22:44:46Z (GMT). No. of bitstreams: 2 VIJITBENJARONK-THESIS-2020.pdf: 338458 bytes, checksum: 15866d2d85ef90bca4c32677fa4ca94c (MD5) LICENSE.txt: 4216 bytes, checksum: 007236c2ae6a4fc665f7dbd270ab3827 (MD5) Previous issue date: 2020-07-22","Embargo set by: Seth Robbins for item 116265 Lift date: 2022-10-07T22:44:53Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","Open Restriction set for Item 116265 on 2021-07-26T14:10:14Z with date null by madinag@illinois.edu.","Open Restriction set for Item 116265 on 2021-07-26T14:10:22Z with date null by madinag@illinois.edu.","Open"]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Provable stability defenses for targeted data poisoning"]}]}],"canonical_facts":{"dc:contributor":["Koyejo, Oluwasanmi"],"dc:creator":["Vijitbenjaronk, Warut D."],"dc:date":["2020-10-07T22:44:46Z","2020-07-22","2020-08"],"dc:description":["Modern machine learning systems are often trained on massive, crowdsourced datasets. Due to the impossibility of checking this data, these systems may be susceptible to data poisoning attacks where malicious users inject false training data in order to influence the learned model. While recent work has focused primarily on the untargeted case, where the attacker's goal is to increase overall error, much less is understood about the theoretical underpinnings of targeted data poisoning attacks. These attacks try to cause the learned model to change its prediction on only a few targeted examples without raising suspicion. We suggest algorithmic stability as a sufficient condition for robustness against data poisoning, construct upper bounds on the possible effectiveness of data poisoning attacks against stable algorithms, and propose an algorithm that provides resilience against popular classes of attacks. Empirically, we report findings on the MNIST 1-7 image classification dataset and the TREC 2007 spam detection dataset that confirms our theoretical findings.","Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2022-08-01","The student, Warut Vijitbenjaronk, accepted the attached license on 2020-07-21 at 21:20.","The student, Warut Vijitbenjaronk, submitted this Thesis for approval on 2020-07-21 at 21:27.","This Thesis was approved for publication on 2020-07-22 at 11:00.","DSpace SAF Submission Ingestion Package generated from Vireo submission #15718 on 2020-10-02 at 15:34:06","Made available in DSpace on 2020-10-07T22:44:46Z (GMT). No. of bitstreams: 2 VIJITBENJARONK-THESIS-2020.pdf: 338458 bytes, checksum: 15866d2d85ef90bca4c32677fa4ca94c (MD5) LICENSE.txt: 4216 bytes, checksum: 007236c2ae6a4fc665f7dbd270ab3827 (MD5) Previous issue date: 2020-07-22","Embargo set by: Seth Robbins for item 116265 Lift date: 2022-10-07T22:44:53Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","Open Restriction set for Item 116265 on 2021-07-26T14:10:14Z with date null by madinag@illinois.edu.","Open Restriction set for Item 116265 on 2021-07-26T14:10:22Z with date null by madinag@illinois.edu.","Open"],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/108638"],"dc:language":["en"],"dc:rights":["Copyright 2020 Warut D. Vijitbenjaronk"],"dc:subject":["data poisoning","machine learning","robust machine learning","stable support vector machine","algorithmic stability","uniform stability","adversarial machine learning"],"dc:title":["Provable stability defenses for targeted data poisoning"],"dc:type":["text","Thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:48Z"}