Timber! Poisoning Decision Trees
Calzavara, Stefano, Cazzaro, Lorenzo, Vettori, Massimo
We present Timber, the first white-box poisoning attack targeting decision trees. Timber is based on a greedy attack strategy leveraging sub-tree retraining to efficiently estimate the damage performed by poisoning a given training instance. The attack relies on a tree annotation procedure which enables sorting training instances so that they are processed in increasing order of computational cost of sub-tree retraining. This sorting yields a variant of Timber supporting an early stopping criterion designed to make poisoning attacks more efficient and feasible on larger datasets. We also discuss an extension of Timber to traditional random forest models, which is useful because decision trees are normally combined into ensembles to improve their predictive power. Our experimental evaluation on public datasets shows that our attacks outperform existing baselines in terms of effectiveness, efficiency or both. Moreover, we show that two representative defenses can mitigate the effect of our attacks, but fail at effectively thwarting them.
Oct-1-2024
- Country:
- Asia
- Japan > Honshū
- Kansai > Osaka Prefecture > Osaka (0.04)
- Middle East > UAE
- Abu Dhabi Emirate > Abu Dhabi (0.04)
- Singapore (0.04)
- Taiwan (0.04)
- Japan > Honshū
- Europe
- Austria (0.04)
- France
- Hauts-de-France > Nord
- Lille (0.04)
- Occitanie > Hérault
- Montpellier (0.04)
- Hauts-de-France > Nord
- Ireland > Leinster
- County Dublin > Dublin (0.04)
- Italy
- Poland > West Pomerania Province
- Szczecin (0.04)
- United Kingdom
- England > Greater London
- London (0.04)
- Scotland > City of Edinburgh
- Edinburgh (0.04)
- England > Greater London
- North America
- Canada
- British Columbia > Metro Vancouver Regional District
- Vancouver (0.04)
- Quebec > Montreal (0.04)
- British Columbia > Metro Vancouver Regional District
- United States
- California
- Los Angeles County > Long Beach (0.14)
- San Diego County > San Diego (0.04)
- San Francisco County > San Francisco (0.14)
- Hawaii > Honolulu County
- Honolulu (0.04)
- Louisiana > Orleans Parish
- New Orleans (0.04)
- Maryland > Baltimore (0.04)
- Texas
- Dallas County > Dallas (0.04)
- Travis County > Austin (0.04)
- California
- Canada
- Oceania > Australia
- New South Wales > Sydney (0.04)
- South America > Brazil
- Rio de Janeiro > Rio de Janeiro (0.04)
- Asia
- Genre:
- Research Report (0.50)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Materials > Paper & Forest Products (1.00)
- Technology: