Title
Automated Attacks on Compression-Based Classifiers
Abstract
Methods of compression-based text classification have proven their usefulness for various applications. However, in some classification problems, such as spam filtering, a classifier confronts one or many adversaries willing to induce errors in the classifier's judgment on certain kinds of input. In this paper, we consider the problem of finding thrifty strategies for character-based text modification that allow an adversary to revert classifier's verdict on a given family of input texts. We propose three statistical statements of the problem that can be used by an attacker to obtain transformation models which are optimal in some sense. Evaluating these three techniques on a realistic spam corpus, we find that an adversary can transform a spam message (detectable as such by an entropy-based text classifier) into a legitimate one by generating and appending, in some cases, as few additional characters as 11% of the original length of the message.
Year
DOI
Venue
2015
10.1145/2808769.2808778
AISec@CCS
Field
DocType
Citations 
Computer science,Filter (signal processing),Adversarial machine learning,Artificial intelligence,Adversary,Classifier (linguistics),Machine learning
Conference
1
PageRank 
References 
Authors
0.35
31
2
Name
Order
Citations
PageRank
Igor Burago131.39
Daniel Lowd258740.95