Data poisoning attacks against autoregressive models

202Citations
Citations of this article
126Readers
Mendeley users who have this article in their library.

Abstract

Forecasting models play a key role in money-making ventures in many different markets. Such models are often trained on data from various sources, some of which may be untrustworthy. An actor in a given market may be incentivised to drive predictions in a certain direction to their own benefit. Prior analyses of intelligent adversaries in a machinelearning context have focused on regression and classification. In this paper we address the non-iid setting of time series forecasting. We consider a forecaster, Bob, using a fixed, known model and a recursive forecasting method. An adversary, Alice, aims to pull Bob's forecasts toward her desired target series, and may exercise limited influence on the initial values fed into Bob's model. We consider the class of linear autoregressive models, and a flexible framework of encoding Alice's desires and constraints. We describe a method of calculating Alice's optimal attack that is computationally tractable, and empirically demonstrate its effectiveness compared to random and greedy baselines on synthetic and realworld time series data. We conclude by discussing defensive strategies in the face of Alice-like adversaries.

Cite

CITATION STYLE

APA

Alfeld, S., Zhu, X., & Barford, P. (2016). Data poisoning attacks against autoregressive models. In 30th AAAI Conference on Artificial Intelligence, AAAI 2016 (pp. 1452–1458). AAAI press. https://doi.org/10.1609/aaai.v30i1.10237

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free