Telecommunications Science ›› 2023, Vol. 39 ›› Issue (7): 46-58.doi: 10.11959/j.issn.1000-0801.2023140

• Research and Development • Previous Articles     Next Articles

Research on filter-based adversarial feature selection against evasion attacks

Qimeng HUANG1,2, Miaomiao WU1,2, Yun LI1,2   

  1. 1 Nanjing University of Posts and Telecommunications, Nanjing 210023, China
    2 Jiangsu Key Laboratory for Big Data Security and Intelligent Processing, Nanjing 210023, China
  • Revised:2023-07-02 Online:2023-07-20 Published:2023-07-01
  • Supported by:
    The National Natural Science Foundation of China(61772284)

Abstract:

With the rapid development and widespread application of machine learning technology, its security has attracted increasing attention, leading to a growing interest in adversarial machine learning.In adversarial scenarios, machine learning techniques are threatened by attacks that manipulate a small number of samples to induce misclassification, resulting in serious consequences in various domains such as spam detection, traffic signal recognition, and network intrusion detection.An evaluation criterion for filter-based adversarial feature selection was proposed, based on the minimum redundancy and maximum relevance (mRMR) method, while considering security metrics against evasion attacks.Additionally, a robust adversarial feature selection algorithm was introduced, named SDPOSS, which was based on the decomposition-based Pareto optimization for subset selection (DPOSS) algorithm.SDPOSS didn’t depend on subsequent models and effectively handles large-scale high-dimensional feature spaces.Experimental results demonstrate that as the number of decompositions increases, the runtime of SDPOSS decreases linearly, while achieving excellent classification performance.Moreover, SDPOSS exhibits strong robustness against evasion attacks, providing new insights for adversarial machine learning.

Key words: adversarial feature selection, evasion attack, mRMR, security assessment criteria, Pareto dominate

CLC Number: 

No Suggested Reading articles found!