Poison Attacks Against Machine Learning
mikejuk writes "Support Vector Machines (SVMs) are fairly simple but powerful machine learning systems. They learn from data and are usually trained before being deployed. SVMs are used in security to detect abnormal behavior such as fraud, credit card use anomalies and even to weed out spam. In many cases they need to continue to learn as they do the job and this raised the possibility of feeding it with data that causes it to make bad decisions. Three researchers have recently demonstrated how to do this with the minimum poisoned data to maximum effect. What they discovered is that their method was capable of having a surprisingly large impact on the performance of the SVMs tested. They also point out that it could be possible to direct the induced errors so as to produce particular types of error. For example, a spammer could send some poisoned data so as to evade detection for a while. AI based systems may be no more secure than dumb ones."
On this side of the human / AI line, we call this propaganda. It has historically proved very effective, specially if you can control all of the "training data."
So if you know the algorithm and training data, and you can feed the system new data with manipulated labels then you can confuse it. It's a little early to panic about your spam filter. Hopefully everyone realizes that if you let the spammers tell your computer what is and is not spam, they can cause it to let their spam through.
When you think about it, whats going on here is inducing mental illness in "thinking" machines.
We already know how to induce mental illness in humans. Religion and war.
Excuse the Unicode crap in my posts. That's an apostrophe, and slashdot is busted.
You mean propaganda and social pressure.
Religion and war are just consequences of those.
Rethinking email