Conference Proceedings
Near-optimal evasion of convex-inducing classifiers
B Nelson, BIP Rubinstein, L Huang, AD Joseph, SH Lau, SJ Lee, S Rao, A Tran, JD Tygar
Journal of Machine Learning Research | Published : 2010
Abstract
Classifiers are often used to detect miscreant activities. We study how an adversary can efficiently query a classifier to elicit information that allows the adversary to evade detection at near-minimal cost. We generalize results of Lowd and Meek (2005) to convex-inducing classifiers. We present algorithms that construct undetected instances of near-minimal cost using only polynomially many queries in the dimension of the space and without reverse engineering the decision boundary. Copyright 2010 by the authors.