Multiple Classifier Systems under Attack

10 years 6 months ago
Multiple Classifier Systems under Attack
Abstract. In adversarial classification tasks like spam filtering, intrusion detection in computer networks and biometric authentication, a pattern recognition system must not only be accurate, but also robust to manipulations of input samples made by an adversary to mislead the system itself. It has been recently argued that the robustness of a classifier could be improved by avoiding to overemphasize or underemphasize input features on the basis of training data, since at operation phase the feature importance may change due to modifications introduced by the adversary. In this paper we empirically investigate whether the well known bagging and random subspace methods allow to improve the robustness of linear base classifiers by producing more uniform weight values. To this aim we use a method for performance evaluation of a classifier under attack that we are currently developing, and carry out experiments on a spam filtering task with several linear base classifiers.
Battista Biggio, Giorgio Fumera, Fabio Roli
Added 14 Oct 2010
Updated 14 Oct 2010
Type Conference
Year 2010
Where MCS
Authors Battista Biggio, Giorgio Fumera, Fabio Roli
Comments (0)