Conference Proceedings

Near-optimal evasion of convex-inducing classifiers

B Nelson, BIP Rubinstein, L Huang, AD Joseph, SH Lau, SJ Lee, S Rao, A Tran, JD Tygar

Journal of Machine Learning Research | Published : 2010

Abstract

Classifiers are often used to detect miscreant activities. We study how an adversary can efficiently query a classifier to elicit information that allows the adversary to evade detection at near-minimal cost. We generalize results of Lowd and Meek (2005) to convex-inducing classifiers. We present algorithms that construct undetected instances of near-minimal cost using only polynomially many queries in the dimension of the space and without reverse engineering the decision boundary. Copyright 2010 by the authors.

University of Melbourne Researchers

Citation metrics