כתבה
arXiv cs.AI ·
שימוש בשיקום לא מושלם להתקפת חסימת גישה לנתונים
Leveraging Imperfect Restoration for Data Availability Attack
במאמר זה, נציגים שיטה חדשה להתקפת חסימת גישה לנתונים, המטרה להפקיע את האפשרות לאימון מודלי למידת מכונה. השיטה, הנקראת Imperfect Restoration Poisoning (IRP), נבחנה בהשוואה לשמונה שיטות בסיסיות ובהשוואה לחמש שיטות הגנה נפרדות.
תקציר מקורי באנגליתarXiv:2609.04627v1 Announce Type: new Abstract: The abundance of online data is at risk of unauthorized usage in training deep learning models. To counter this, various Data Availability Attacks (DAAs) have been devised to make data unlearnable for such models by subtly perturbing the training data. However, existing attacks often excel against either Supervised Learning (SL) or Self-Supervised Learning (SSL) scenarios. Among these, a model-free approach that generates a Convolution-based Unlearnable Dataset (CUDA) stands out as the most robust DAA across both SSL and SL. Nonetheless, CUDA's effectiveness against SSL is underwhelming and it faces a severe trade-off between image quality and its poisoning effect. In this paper, we conduct a theoretical analysis of CUDA, uncovering the sub-o
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית