2021

Availability Attacks Create Shortcuts

Yu, Da, Zhang, Huishuai, Chen, Wei et al.

Understand

Availability attacks, which poison the training data with imperceptible perturbations, can make the data \emph{not exploitable} by machine learning algorithms so as to prevent unauthorized use of data.

  • In this work, we investigate why these perturbations work in principle.
  • We are the first to unveil an important population property of the perturbations of these attacks: they are almost \textbf{linearly separable} when assigned with the target labels of the corresponding samples, which hence can work as \emph{shortcuts} for the learning objective.
  • We further verify that linear separability is indeed the workhorse for availability attacks.

Reading the bibliography…