AIセキュリティポータル K Program
Efficient Availability Attacks against Supervised and Contrastive Learning Simultaneously
Share
Abstract
Availability attacks can prevent the unauthorized use of private data and commercial datasets by generating imperceptible noise and making unlearnable examples before release. Ideally, the obtained unlearnability prevents algorithms from training usable models. When supervised learning (SL) algorithms have failed, a malicious data collector possibly resorts to contrastive learning (CL) algorithms to bypass the protection. Through evaluation, we have found that most of the existing methods are unable to achieve both supervised and contrastive unlearnability, which poses risks to data protection. Different from recent methods based on contrastive error minimization, we employ contrastive-like data augmentations in supervised error minimization or maximization frameworks to obtain attacks effective for both SL and CL. Our proposed AUE and AAP attacks achieve state-of-the-art worst-case unlearnability across SL and CL algorithms with less computation consumption, showcasing prospects in real-world applications.
Wild Patterns: Ten Years After the Rise of Adversarial Machine Learning
Battista Biggio, Fabio Roli
Published: 2017.12.9
Self-ensemble protection: Training checkpoints are good data protectors
S. Chen, G. Yuan, X. Cheng, Y. Gong, M. Qin, Y. Wang, X. Huang
Published: 2023
A simple framework for contrastive learning of visual representations
T. Chen, S. Kornblith, M. Norouzi, G. Hinton
Published: 2020
Exploring simple siamese representation learning
X. Chen, K. He
Published: 2021
The Devil's Advocate: Shattering the Illusion of Unexploitable Data using Diffusion Models
Hadi M. Dolatabadi, Sarah Erfani, Christopher Leckie
Published: 2023.3.15
Learning to Confuse: Generating Training Time Adversarial Data with Auto-Encoder
Ji Feng, Qi-Zhi Cai, Zhi-Hua Zhou
Published: 2019.5.22
Adversarial examples make strong poisons
Liam Fowl, Micah Goldblum, Ping-yeh Chiang, Jonas Geiping, Wojciech Czaja, Tom Goldstein
Published: 2021
Robust unlearnable examples: Protecting data privacy against adversarial learning
Shaopeng Fu, Fengxiang He, Yang Liu, Li Shen, Dacheng Tao
Published: 2022
Bootstrap your own latent-a new approach to self-supervised learning
J.-B. Grill, F. Strub, F. Altche, C. Tallec, P. Richemond, E. Buchatskaya, C. Doersch, B. Avila Pires, Z. Guo, M. Gheshlaghi Azar
Published: 2020
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, Jian Sun
Published: 2016
Momentum contrast for unsupervised visual representation learning
K. He, H. Fan, Y. Wu, S. Xie, R. Girshick
Published: 2020
Densely connected convolutional networks
G. Huang, Z. Liu, L. Van Der Maaten, K. Q. Weinberger
Published: 2017
Unlearnable examples: Making personal data unexploitable
Hanxun Huang, Xingjun Ma, Sarah Monazam Erfani, James Bailey, Yisen Wang
Published: 2021
Supervised contrastive learning
P. Khosla, P. Teterwak, C. Wang, A. Sarna, Y. Tian, P. Isola, A. Maschinot, C. Liu, D. Krishnan
Published: 2020
Adversarial Self-Supervised Contrastive Learning
Minseon Kim, Jihoon Tack, Sung Ju Hwang
Published: 2020.6.13
Learning multiple layers of features from tiny images
Alex Krizhevsky, Geoffrey Hinton
Published: 2009
Tiny imagenet visual recognition challenge
Y. Le, X. Yang
Published: 2015
Game-Theoretic Unlearnable Example Generator
Shuang Liu, Yihan Wang, Xiao-Shan Gao
Published: 2024.1.31
Transferable Availability Poisoning Attacks
Yiyong Liu, Michael Backes, Xiao Zhang
Published: 2023.10.8
Image shortcut squeezing: Countering perturbative availability poisons with compression
Zhuoran Liu, Zhengyu Zhao, Martha Larson
Published: 2023
Towards Deep Learning Models Resistant to Adversarial Attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, Adrian Vladu
Published: 2017.6.20
Transferable unlearnable examples
J. Ren, H. Xu, Y. Wan, X. Ma, L. Sun, J. Tang
Published: 2022
Kornia: an open source differentiable computer vision library for pytorch
E. Riba, D. Mishkin, D. Ponsa, E. Rublee, G. Bradski
Published: 2020
Imagenet large scale visual recognition challenge
Russakovsky, O., Deng, J., Su, H., Krause, J., Satheesh, S., Ma, S., Huang, Z., Karpathy, A., Khosla, A., Bernstein, M., et al.
Published: 2015
Cuda: Convolution-based unlearnable datasets
V. S. Sadasivan, M. Soltanolkotabi, S. Feizi
Published: 2023
Mobilenetv2: Inverted residuals and linear bottlenecks
M. Sandler, A. Howard, M. Zhu, A. Zhmoginov, L.-C. Chen
Published: 2018
Autoregressive perturbations for data poisoning
Pedro Sandoval-Segura, Vasu Singla, Jonas Geiping, Micah Goldblum, Tom Goldstein, David W. Jacobs
Published: 2022
Very deep convolutional networks for large-scale image recognition
K. Simonyan, A. Zisserman
Published: 2015
Fixmatch: Simplifying semi-supervised learning with consistency and confidence
K. Sohn, D. Berthelot, N. Carlini, Z. Zhang, H. Zhang, C. A. Raffel, E. D. Cubuk, A. Kurakin, C.-L. Li
Published: 2020
Better safe than sorry: Preventing delusive adversaries with adversarial training
Lue Tao, Lei Feng, Jinfeng Yi, Sheng-Jun Huang, Songcan Chen
Published: 2021
Can adversarial training be manipulated by non-robust features?
L. Tao, L. Feng, H. Wei, J. Yi, S.-J. Huang, S. Chen
Published: 2022
Matching networks for one shot learning
O. Vinyals, C. Blundell, T. Lillicrap, D. Wierstra
Published: 2016
Understanding contrastive representation learning through alignment and uniformity on the hypersphere
T. Wang, P. Isola
Published: 2020
Is adversarial training really a silver bullet for mitigating data poisoning?
R. Wen, Z. Zhao, Z. Liu, M. Backes, T. Wang, Y. Zhang
Published: 2023
One-pixel shortcut: On the learning preference of deep neural networks
S. Wu, S. Chen, C. Xie, X. Huang
Published: 2022
Unsupervised feature learning via non-parametric instance discrimination
Z. Wu, Y. Xiong, S. X. Yu, D. Lin
Published: 2018
Availability Attacks Create Shortcuts
Da Yu, Huishuai Zhang, Wei Chen, Jian Yin, Tie-Yan Liu
Published: 2021.11.1
Neural tangent generalization attacks
C.-H. Yuan, S.-H. Wu
Published: 2021
Unlearnable clusters: Towards label-agnostic unlearnable examples
J. Zhang, X. Ma, Q. Yi, J. Sang, Y.-G. Jiang, Y. Wang, C. Xu
Published: 2023
Share