Incompatibility Clustering as a Defense Against Backdoor Poisoning Attacks
Charles Jin; Melinda Sun; Martin Rinard · 2021 · arXiv
WASTE classifies this as Negative / Null Result Report · AI classification, approximate
The study found no significant effect — useful as a negative control or null benchmark for your own design.
Abstract (excerpt)
We propose a novel clustering mechanism based on an incompatibility property between subsets of data that emerges during model training. This mechanism partitions the dataset into subsets that generalize only to themselves, i.e., training on one subset does not improve performance on the other subsets. Leveraging the interaction between the dataset and the training process, our clustering mechanism partitions datasets into clusters that are defined by--and therefore meaningful to--the objective of the training process. We apply our clustering mechanism to defend against data poisoning attacks,
Excerpt shown for reference under fair use — read the full paper at the publisher.
About to run something similar?
Run an AI Precheck on your own design to catch failure modes like this one before you spend the time. Your first desk check is free.
Related failures
Leakage and the reproducibility crisis in machine-learning-based science
Negative / Null Result ReportDefining and detecting quantum speedup
Negative / Null Result ReportService robots in hotels: understanding the service quality perceptions of human-robot interaction
Negative / Null Result ReportBoosting methods for multi-class imbalanced data classification: an experimental review
Negative / Null Result ReportFINANCIAL DEVELOPMENT AND ECONOMIC GROWTH: A META‐ANALYSIS
Negative / Null Result ReportThe impact of site-specific digital histology signatures on deep learning model accuracy and bias
WASTE indexes this work — it does not host or republish it. Failure-type classification is automated and approximate.
Metadata source: arXiv
