PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
August 22, 2004906 citations

Adversarial classification

View Full Paper
NDNilesh DalviJ. S. Ayurveda Mahavidyalaya and P.D. Patel Ayurveda HospitalPDPedro DomingosUniversitas Nusa BangsaMMMausam MausamArtificial Intelligence in Medicine (Canada)

Key Points

Key points are not available for this paper at this time.

Abstract

Essentially all data mining algorithms assume that the data-generating process is independent of the data miner's activities. However, in many domains, including spam detection, intrusion detection, fraud detection, surveillance and counter-terrorism, this is far from the case: the data is actively manipulated by an adversary seeking to make the classifier produce false negatives. In these domains, the performance of a classifier can degrade rapidly after it is deployed, as the adversary learns to defeat it. Currently the only solution to this is repeated, manual, ad hoc reconstruction of the classifier. In this paper we develop a formal framework and algorithms for this problem. We view classification as a game between the classifier and the adversary, and produce a classifier that is optimal given the adversary's optimal strategy. Experiments in a spam detection domain show that this approach can greatly outperform a classifier learned in the standard way, and (within the parameters of the problem) automatically adapt the classifier to the adversary's evolving manipulations.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Dalvi et al. (2004) studied this question.

synapsesocial.com/papers/6a08caae60378a53cb66bbfehttps://doi.org/10.1145/1014052.1014066
Ask AI
Helpful
Bookmark
Share
View Full Paper