Skip to main navigation Skip to search Skip to main content

Jangseung: A Guardian for Machine Learning Algorithms to Protect against Poisoning Attacks

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

5 Scopus citations

Abstract

Many smart city applications rely on machine learning; however, adversarial perturbations can be injected into training data to cause models to return skewed results. Jangseung is a preprocessor limits the effects of poisoning attacks without impeding on accuracy. Jangseung was created to guard support vector machines from poisoned data by utilizing anomaly detection algorithms. The preprocessor was tested through experiments that utilized two different datasets, the MNIST dataset and the UCI breast cancer Wisconsin (diagnostic) dataset. With both datasets, two identical models were trained and then attacked using the same adversarial points, one with Jangseung protecting it and the other unguarded from attack. In all cases, the protected model out-performed the unprotected model and in the best case scenario, the Jangseung-protected model outperformed the unguarded model by 96.2%. The under-trained, undefended MNIST models had an average accuracy of 53.2%. When Jangseung was present, their identical counterparts had a drastically higher average accuracy at 91.1%. Likewise, in the UCI-Cancer dataset, attack sequences lowered the accuracy of the model to as low as 75.51%, but Jangseung-defended models performed with 88.18% accuracy or better. Jangseung was an effective defense against adversarial perturbations for SVMs using different datasets and anomaly detection algorithms.

Original languageEnglish
Title of host publication2021 IEEE International Smart Cities Conference, ISC2 2021
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781665449199
DOIs
StatePublished - Sep 7 2021
Externally publishedYes
Event2021 IEEE International Smart Cities Conference, ISC2 2021 - Manchester, United Kingdom
Duration: Sep 7 2021Sep 10 2021

Publication series

Name2021 IEEE International Smart Cities Conference, ISC2 2021

Conference

Conference2021 IEEE International Smart Cities Conference, ISC2 2021
Country/TerritoryUnited Kingdom
CityManchester
Period09/7/2109/10/21

Keywords

  • Adversarial Perturbations
  • Poisoning Defense
  • Smart City Applications

Fingerprint

Dive into the research topics of 'Jangseung: A Guardian for Machine Learning Algorithms to Protect against Poisoning Attacks'. Together they form a unique fingerprint.

Cite this