The increasing access to data poses both opportunities and risks in deep learning, as one can manipulate the behaviors of deep learning models with malicious training samples. Such attacks are known as data poisoning. Recent advances in defense strategies against data poisoning have highlighted the effectiveness of aggregation schemes in achieving state-of-the-art results in certified poisoning robustness. However, the practical implications of these approaches remain unclear. Here we focus on Deep Partition Aggregation, a representative aggregation defense, and assess its practical aspects, including efficiency, performance, and robustness. For evaluations, we use ImageNet resized to a resolution of 64 by 64 to enable evaluations at a larger scale than previous ones. Firstly, we demonstrate a simple yet practical approach to scaling base models, which improves the efficiency of training and inference for aggregation defenses. Secondly, we provide empirical evidence supporting the data-to-complexity ratio, i.e. the ratio between the data set size and sample complexity, as a practical estimation of the maximum number of base models that can be deployed while preserving accuracy. Last but not least, we point out how aggregation defenses boost poisoning robustness empirically through the poisoning overfitting phenomenon, which is the key underlying mechanism for the empirical poisoning robustness of aggregations. Overall, our findings provide valuable insights for practical implementations of aggregation defenses to mitigate the threat of data poisoning.
翻译:在深度学习领域,数据获取渠道的日益增多既带来了机遇也伴随着风险——攻击者可通过恶意训练样本操纵模型行为,此类攻击被称为数据投毒。近期针对数据投毒防御策略的研究表明,聚合方案在实现认证投毒鲁棒性方面取得了最佳成果。然而,这些方法的实际应用效果仍不明确。本文聚焦于具有代表性的聚合防御方法——深度分区聚合,从效率、性能和鲁棒性三个维度评估其实际应用价值。我们采用分辨率调整为64×64的ImageNet数据集进行更大规模的评估实验。首先,提出一种简单实用的基础模型扩展方法,有效提升了聚合防御框架的训练与推理效率。其次,通过实证研究验证了数据复杂度比(即数据集规模与样本复杂度之比)可作为实际部署中兼顾准确性的基础模型最大数量的实用估算指标。最后,我们揭示了聚合防御通过"投毒过拟合"现象增强鲁棒性的实证机制——这是聚合方法获得实证投毒鲁棒性的关键运作机理。综合而言,本研究为实际部署聚合防御方案以应对数据投毒威胁提供了重要实践指导。