DynaDetect2.0: Improving Detection Accuracy of Data Poisoning Attacks

Sabrina Perry, Yili Jiang, Fangtian Zhong, Jiaqi Huang, Sohan Gyawali · 2024

Machine learning (ML) models have become pivotal in various sectors, making their security and reliability increasingly important. Data poisoning attacks corrupt training data and pose significant threats to model integrity and performance. Traditional K-Nearest Neighbor (KNN) is vulnerable to these attacks due to its fixed selection of the k value, which limits its ability to adapt to poisoned data. To address this challenge, DynaDetect [1], a dynamic KNN-based detection algorithm, was designed by adjusting k values dynamically. To further improve the detection accuracy of DynaDetect, in this work, we propose DynaDetect2.0, an improved version that builds on the original DynaDetect by incorporating Convolutional Neural Networks (CNN) for feature extraction and utilizing advanced distance metrics, including Mean Squared Error (MSE) and Mahalanobis distance. These improvements enable DynaDetect2.0 to better adapt to attack patterns and significantly increase detection accuracy. Through extensive experimentation, its results indicate that DynaDetect2.0 outperforms both DynaDetect and traditional KNN on diverse datasets such as CIFAR-10, ImageNet, and GTSRB. Specifically, DynaDetect2.0 shows a 34.3% improvement over DynaDetect algorithm and a 106.7% improvement over traditional KNN. This research provides a robust framework for detecting data poisoning attacks in ML models, addressing critical gaps in current detection methods.

Read the paper · More papers on PaperTik