Stealthy Poisoning Attacks Bypass Defenses in Regression Settings

📅 2026-01-29
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the vulnerability of existing regression models to stealthy data poisoning attacks, which often evade detection under unrealistic threat assumptions prevalent in prior research. We present the first systematic characterization of covert poisoning attacks across varying detectability levels and introduce a target-normalization-based evaluation framework to rigorously quantify the trade-off between attack efficacy and detectability, enabling the construction of optimal stealthy attacks. To counter this threat, we propose BayesClean, a novel Bayesian defense mechanism that integrates robust regression with Bayesian inference. Extensive experiments demonstrate that BayesClean significantly outperforms state-of-the-art defenses under high-stealth, large-scale poisoning scenarios and effectively mitigates attacks that circumvent current defense strategies.

Technology Category

Application Category

📝 Abstract
Regression models are widely used in industrial processes, engineering and in natural and physical sciences, yet their robustness to poisoning has received less attention. When it has, studies often assume unrealistic threat models and are thus less useful in practice. In this paper, we propose a novel optimal stealthy attack formulation that considers different degrees of detectability and show that it bypasses state-of-the-art defenses. We further propose a new methodology based on normalization of objectives to evaluate different trade-offs between effectiveness and detectability. Finally, we develop a novel defense (BayesClean) against stealthy attacks. BayesClean improves on previous defenses when attacks are stealthy and the number of poisoning points is significant.
Problem

Research questions and friction points this paper is trying to address.

stealthy poisoning attacks
regression models
robustness
detectability
defenses
Innovation

Methods, ideas, or system contributions that make the work stand out.

stealthy poisoning attacks
regression robustness
objective normalization
BayesClean
detectability trade-off
🔎 Similar Papers
No similar papers found.
J
Javier Carnerero-Cano
IBM Research Europe, Portal, First Floor Trinity Business School, Trinity College Dublin, Dublin, D02 F6N2, Ireland; Work done while with Imperial College London, South Kensington Campus, London, SW7 2AZ, United Kingdom
L
Luis Munoz-Gonzalez
Universidad de Alcalá, Escuela Politécnica Superior, Alcalá de Henares, 28805, Spain; Work done while with Imperial College London, South Kensington Campus, London, SW7 2AZ, United Kingdom
P
P. Spencer
BAE Systems Air, United Kingdom; Work done while with the Defence Science and Technology Laboratory (DSTL), Porton Down, Salisbury, United Kingdom
E
Emil C. Lupu
Imperial College London, South Kensington Campus, London, SW7 2AZ, United Kingdom