Stealthy Poisoning Attacks Bypass Defenses in Regression Settings
This work addresses the vulnerability of existing regression models to stealthy data poisoning attacks, which often evade detection under unrealistic threat assumptions prevalent in prior research. We present the first systematic characterization of covert poisoning attacks across varying detectability levels and introduce a target-normalization-based evaluation framework to rigorously quantify the trade-off between attack efficacy and detectability, enabling the construction of optimal stealthy attacks. To counter this threat, we propose BayesClean, a novel Bayesian defense mechanism that integrates robust regression with Bayesian inference. Extensive experiments demonstrate that BayesClean significantly outperforms state-of-the-art defenses under high-stealth, large-scale poisoning scenarios and effectively mitigates attacks that circumvent current defense strategies.