Online AutoML: Evaluating Poisoning Attacks on Adversarial Training Defense Strategy in IoT Networks
Authors: Chukwunonso Henry Nwokoye, Khalil El-Khatib, Li Yang
Organizations: Faculty of Business and Information Technology, Ontario Tech University, Oshawa, Ontario, Canada · Department of Computer Science, Alex Ekwueme Federal University, Nigeria
Machine learning (ML)-powered poisoning attack vectors are adversarial maneuvers whereby an attacker intentionally inserts, corrupts, or alters training data to distort an ML model's learning process. The objective is to diminish model efficacy, instill biases, induce misclassifications, or include concealed backdoors that may be attacked during implementation. In streaming contexts, poisoning attacks pose significant risks since models perpetually update based on incoming streams of data. An assailant may incrementally introduce harmful samples into this data stream, leading the model to assimilate erroneous features over time without timely identification. Therefore, this study is aimed at evaluating the efficacy of the adversarial training (AT) defense approach against poisoning attacks (label flip and noise injection) using an online AutoML pipeline for Internet of Things (IoT) networks. Specifically, poisoning attacks (label flip and noise injection) were applied to streaming-capable AutoML learners (Hoeffding Tree (HT), Leveraging Bagging (LB), Adaptive Random Forest (ARF), Hoeffding Adaptive Tree (HAT), and Streaming Random Patches (SRP)). Under the strongest poisoning rate (PR = 1.0), AT-SRP achieved the highest F1-score against label flip poisoning (0.904), while AT-LB achieved the highest F1-score against noise-injection poisoning (0.933). Finally, several drift detection methods were used for rolling accuracy and prequential evaluation.
Figures & tables
Fig. 1: The overview of the proposed framework
Classifier
Rate
Accuracy
F1
Precision
Recall
Hoeffding Tree
0.0
0.942
0.914
0.888
0.942
Hoeffding Tree
0.4
0.942
0.914
0.888
0.942
Hoeffding Tree
1.0
0.058
0.006
0.003
0.058
Leveraging Bagging
0.0
0.898
0.911
0.928
0.898
Leveraging Bagging
0.4
0.191
0.259
0.857
0.191
Leveraging Bagging
1.0
0.058
0.006
0.003
0.058
TABLE I: Naive Model Performance Under Label-Flip Poisoning
Classifier
Rate
Accuracy
F1
Precision
Recall
Hoeffding Tree
0.0
0.058
0.006
0.003
0.058
Hoeffding Tree
0.4
0.058
0.006
0.003
0.058
Hoeffding Tree
1.0
0.058
0.006
0.003
0.058
Leveraging Bagging
0.0
0.429
0.550
0.905
0.429
Leveraging Bagging
0.4
0.296
0.409
0.860
0.296
Leveraging Bagging
1.0
0.543
0.661
0.871
0.543
TABLE II: AT Model Performance Under Label-Flip Poisoning
Classifier
Rate
Accuracy
F1
Precision
Recall
Hoeffding Tree
0.0
0.942
0.914
0.888
0.942
Hoeffding Tree
0.4
0.905
0.922
0.951
0.905
Hoeffding Tree
1.0
0.942
0.914
0.888
0.942
Leveraging Bagging
0.0
0.894
0.909
0.930
0.894
Leveraging Bagging
0.4
0.607
0.709
0.936
0.607
Leveraging Bagging
1.0
0.942
0.937
0.934
0.942
TABLE III: Naive Model Performance Under Noise-Injection Poisoning
Classifier
Rate
Accuracy
F1
Precision
Recall
Hoeffding Tree
0.0
0.686
0.769
0.907
0.686
Hoeffding Tree
0.4
0.718
0.791
0.905
0.718
Hoeffding Tree
1.0
0.721
0.793
0.905
0.721
Leveraging Bagging
0.0
0.948
0.952
0.958
0.948
Leveraging Bagging
0.4
0.904
0.921
0.952
0.904
Leveraging Bagging
1.0
0.936
0.933
0.930
0.936
TABLE IV: Adversarially Trained Model Performance Under Noise-Injection Poisoning
Fig. 2: Accuracies and Poisoning Rates
Poisoning Attack
Best AT Model
Rate
Accuracy
Precision
Recall
F1
Label Flip
SRPClassifier
1.0
0.906
0.902
0.906
0.904
Noise Injection
Leveraging Bagging
1.0
0.936
0.930
0.936
0.933
TABLE V: Best AT Models Under Poisoning Attacks
Classifier
Attack
Naive-EDDM
AT-EDDM
HoeffdingTree
label_flip
13/13/10
10/10/10
HoeffdingTree
noise_injection
13/0/13
6/0/0
LeveragingBagging
label_flip
0/15/10
1/9/0
LeveragingBagging
noise_injection
0/24/0
3/2/0
SRPClassifier
label_flip
2/5/7
0/0/2
SRPClassifier
noise_injection
13/1/0
0/0/0
TABLE VI: EDDM Drift Detection Under Poisoning Attacks
Model
PR
Attack
Total Drift (EDDM)
Overlap
Leveraging Bagging Classifier
Naïve-LB
0.4
NI
24
1
AT-LB
0.4
NI
2
1
AT-LB
0.6
NI
1
1
SRP Classifier
AT-SRP
0.2
NI
1
1
TABLE VII: Poisoning Attack Results and Drift Detection
Model
PR
Acc
F1
Prec
Rec
Overlap
Leveraging Bagging
Naïve-LB
0.4
0.607
0.709
0.936
0.607
1
AT-LB
0.4
0.904
0.921
0.952
0.904
1
AT-LB
0.6
0.903
0.921
0.952
0.903
1
SRP Classifier
AT-SRP
0.2
0.950
0.950
0.950
0.950
1
TABLE VIII: Model Performance for Noise-Injection Cases With Drift-Poison Overlap
Fig. 3: Drift Detection for Naive-LB Model
Fig. 4: Drift Detection for AT-LB Model
Classifier
Acc.
F1
Hoeffding Tree
0.058
0.006
Leveraging Bagging
0.543
0.661
SRPClassifier
0.906
0.904
Hoeffding Adaptive Tree
0.703
0.778
Adaptive Random Forest
0.058
0.006
TABLE IX: AT Performance Under Label-Flip Poisoning at Rate 1.0
Classifier
Acc.
F1
Hoeffding Tree
0.721
0.793
Leveraging Bagging
0.936
0.933
SRPClassifier
0.943
0.925
Hoeffding Adaptive Tree
0.803
0.848
Adaptive Random Forest
0.942
0.914
TABLE X: AT Performance Under Noise Injection at Rate 1.0
Minot State University · Department of Math, Data & Technology Minot State University Minot, ND, 58707 · Trustworthy Language Intelligence Lab, Minot State University