Poisoning Bayesian Inference via Data Deletion and Replication

📅 2025-03-06
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work exposes the vulnerability of Bayesian statistical models to data-deletion-and-duplication (DDD) poisoning attacks in white-box adversarial settings: an attacker can arbitrarily steer the posterior distribution toward any target by selectively deleting and duplicating observed data points. We propose, for the first time, a “surgical” model poisoning framework grounded in DDD operations—enabling targeted corruption of specific inference tasks while preserving the integrity of all other inferences. Our method integrates a sampling-driven posterior perturbation algorithm with analytical posterior sensitivity analysis. Extensive experiments on synthetic and real-world datasets demonstrate that the attack is low-cost, broadly applicable across diverse Bayesian models—including Bayesian linear regression, logistic regression, and Gaussian processes—and effectively distorts posterior beliefs. In high-risk configurations, it achieves near-exact posterior shaping, underscoring severe implications for trust in Bayesian inference under adversarial conditions.

Technology Category

Machine Learning: Bayesian LearningReasoning under Uncertainty: Relational Probabilistic ModelsComputer Vision: Adversarial Attacks & Robustness

Application Category

User Modeling, Personalization and Recommendation: Attacks and countermeasures in recommendation systemsGraph Algorithms and Modeling for the Web: Foundation models and LLMs for Web-related graphsWeb Mining and Content Analysis: Large pretrained models with web data
📝 Abstract
Research in adversarial machine learning (AML) has shown that statistical models are vulnerable to maliciously altered data. However, despite advances in Bayesian machine learning models, most AML research remains concentrated on classical techniques. Therefore, we focus on extending the white-box model poisoning paradigm to attack generic Bayesian inference, highlighting its vulnerability in adversarial contexts. A suite of attacks are developed that allow an attacker to steer the Bayesian posterior toward a target distribution through the strategic deletion and replication of true observations, even when only sampling access to the posterior is available. Analytic properties of these algorithms are proven and their performance is empirically examined in both synthetic and real-world scenarios. With relatively little effort, the attacker is able to substantively alter the Bayesian's beliefs and, by accepting more risk, they can mold these beliefs to their will. By carefully constructing the adversarial posterior, surgical poisoning is achieved such that only targeted inferences are corrupted and others are minimally disturbed.
Problem

Research questions and friction points this paper is trying to address.

Extend white-box model poisoning to Bayesian inference
Develop attacks to manipulate Bayesian posterior via data deletion and replication
Demonstrate vulnerability of Bayesian models in adversarial contexts
Innovation

Methods, ideas, or system contributions that make the work stand out.

Extends white-box model poisoning to Bayesian inference
Uses data deletion and replication for posterior manipulation
Achieves surgical poisoning with minimal disturbance