Attackability Characterization of Adversarial Evasion Attack on Discrete Data

17Citations
Citations of this article
26Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Evasion attack on discrete data is a challenging, while practically interesting research topic. It is intrinsically an NP-hard combinatorial optimization problem. Characterizing the conditions guaranteeing the solvability of an evasion attack task thus becomes the key to understand the adversarial threat. Our study is inspired by the weak submodularity theory. We characterize the attackability of a targeted classifier on discrete data in evasion attack by bridging the attackability measurement and the regularity of the targeted classifier. Based on our attackability analysis, we propose a computationally efficient orthogonal matching pursuit-guided attack method for evasion attack on discrete data. It provides provably computational efficiency and attack performances. Substantial experimental results on real-world datasets validate the proposed attackability conditions and the effectiveness of the proposed attack method.

Cite

CITATION STYLE

APA

Wang, Y., Han, Y., Bao, H., Shen, Y., Ma, F., Li, J., & Zhang, X. (2020). Attackability Characterization of Adversarial Evasion Attack on Discrete Data. In Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (pp. 1415–1425). Association for Computing Machinery. https://doi.org/10.1145/3394486.3403194

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free