Evasion Attacks Against Bayesian Predictive Models

📅 2025-06-11
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work systematically exposes the robustness deficiencies of Bayesian predictive models under adversarial conditions, focusing on two critical attack objectives: perturbation of point predictions and manipulation of posterior predictive distributions. We introduce the first unified theoretical framework for Bayesian evasion attacks, proposing a differentiable gradient-based method that preserves uncertainty-aware modeling properties—overcoming the limitation of conventional attacks designed solely for deterministic models. Our approach leverages variational inference and Monte Carlo gradient estimation to enable end-to-end optimization of adversarial perturbations against Bayesian neural networks and Gaussian processes. Experiments demonstrate that the proposed attacks significantly degrade prediction confidence and distort the shape of posterior predictive distributions, thereby revealing deep-seated model vulnerabilities. The results provide both theoretical foundations and empirical evidence for robustness evaluation and defense of Bayesian models.

Technology Category

Machine Learning: Adversarial Learning & RobustnessComputer Vision: Adversarial Attacks & RobustnessGame Theory and Economic Paradigms: Adversarial Learning

Application Category

User Modeling, Personalization and Recommendation: Attacks and countermeasures in recommendation systemsGraph Algorithms and Modeling for the Web: Foundation models and LLMs for Web-related graphsSearch and Retrieval-Augmented AI: Web learning to rank, online learning, and counterfactual learning for ranking
📝 Abstract
There is an increasing interest in analyzing the behavior of machine learning systems against adversarial attacks. However, most of the research in adversarial machine learning has focused on studying weaknesses against evasion or poisoning attacks to predictive models in classical setups, with the susceptibility of Bayesian predictive models to attacks remaining underexplored. This paper introduces a general methodology for designing optimal evasion attacks against such models. We investigate two adversarial objectives: perturbing specific point predictions and altering the entire posterior predictive distribution. For both scenarios, we propose novel gradient-based attacks and study their implementation and properties in various computational setups.
Problem

Research questions and friction points this paper is trying to address.

Study evasion attacks on Bayesian predictive models
Design optimal attacks targeting point predictions
Develop gradient-based attacks for posterior distribution alteration
Innovation

Methods, ideas, or system contributions that make the work stand out.

General methodology for optimal evasion attacks
Gradient-based attacks on point predictions
Gradient-based attacks altering predictive distributions
🔎 Similar Papers
No similar papers found.
P
Pablo G. Arce
Inst. Math. Sciences, Spanish Nat. Research Council, Madrid, Spain; Universidad Autónoma de Madrid, Escuela de Doctorado, Madrid, Spain
Roi Naveiro
Roi Naveiro
CUNEF Universidad
Probabilistic Machine LearningAdversarial Machine LearningBayesian StatisticsDecision Analysis
D
David Ríos Insua
Inst. Math. Sciences, Spanish Nat. Research Council, Madrid, Spain