2020/11/18 by Eitan Borgnia, Valeriia Cherepanova, Borgnia, Eitan +13 · 2 citations
Computer Science · #Adversarial Robustness in Machine Learning #Anomaly Detection Techniques and Applications #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Machine Learning (cs.LG) #Network Security and Intrusion Detection
paper · pdf · doi:10.48550/arxiv.2011.09527
openalex publication_date 2020/11/18 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
Data poisoning and backdoor attacks manipulate victim models by maliciously\nmodifying training data. In light of this growing threat, a recent survey of\nindustry professionals revealed heightened fear in the private sector regarding\ndata poisoning. Many previous defenses against poisoning either fail in the\nface of increasingly strong attacks, or they significantly degrade performance.\nHowever, we find that strong data augmentations, such as mixup and CutMix, can\nsignificantly diminish the threat of poisoning and backdoor attacks without\ntrading off performance. We further verify the effectiveness of this simple\ndefense against adaptive poisoning methods, and we compare to baselines\nincluding the popular differentially private SGD (DP-SGD) defense. In the\ncontext of backdoors, CutMix greatly mitigates the attack while simultaneously\nincreasing validation accuracy by 9%.\n