Poisoning Attacks against Support Vector Machines

Battista BiggioBlaine NelsonPavel Laskov

article2012ICML1,884 citationsTest of Time Award (ICML 2022)

Proposes a gradient-based poisoning attack that generates malicious training data to maximize validation error, demonstrating how intelligent adversaries can systematically subvert Support Vector Machines across linear and non-linear kernels.

Listen

Machine learning systems are widely deployed in security-critical environments, such as spam filtering, malware classification, and intrusion detection. However, standard learning models implicitly assume that training data originates from a benign, well-behaved distribution. In adversarial contexts, attackers can manipulate the data fed into these systems. The article addresses the emerging threat of data poisoning, a scenario where malicious actors deliberately inject corrupted samples into training sets to degrade classifier performance.

The objective of the article is to formulate and demonstrate an optimization framework that generates highly effective malicious training points to systematically degrade the classification accuracy of Support Vector Machines (SVMs), a standard machine learning model.

To achieve this, the authors developed a gradient ascent algorithm that computes how an injected sample shifts the optimal decision boundary of an SVM. Unlike previous approaches that could only design attacks within abstract internal feature representations, this method operates directly in the raw input space across linear and non-linear configurations. The attack was tested on synthetic two-dimensional datasets as well as real-world image classification benchmarks (using the MNIST handwritten digit repository) by establishing a baseline model, selecting an initial mislabeled point, and iteratively modifying it to maximize classification error.

The experimental findings show that deliberate data poisoning is exceptionally potent. First, the gradient-based optimization successfully identified local maxima on the error surface, causing far greater disruption than random label flipping or random noise. Second, injecting just a single optimized attack point into an MNIST classifier caused the testing error rate to spike from a baseline of 2–5% up to 15–20%, effectively quadrupling error rates. Third, in multi-point poisoning experiments, model degradation scaled steadily as the percentage of contaminated training data increased, consistently undermining system reliability.

These findings have critical operational and security implications. They indicate that machine learning pipelines that automatically retrain on externally ingested data—such as spam reporting feeds or malware collection repositories—face severe vulnerability risks. A small fraction of crafted inputs can critically impair automated classification systems, leading to substantial risks of missed threats, inflated manual review costs, and reduced trust in automated defenses. The article highlights that standard classifiers cannot be assumed secure by default against training-time manipulation.

Organizations utilizing machine learning in security-sensitive workflows should prioritize data integrity verification and develop adversarial defense mechanisms before relying on automated retraining pipelines. Future research must expand from single-point attacks to simultaneous multi-point generation and explore real-world input constraints. Key limitations of this analysis include the assumption of full attacker access to training data distributions and direct control over target labels, which may not hold in human-moderated environments. Nonetheless, confidence in the findings is strong, providing definitive proof that SVM algorithms are fundamentally vulnerable to structured poisoning attacks.

arXiv: 1206.6389pralab/secml
  • Paper: Choosing Multiple Parameters for Support Vector Machines, OLIVIER CHAPELLE et al. (2002). This work establishes gradient-based optimization techniques for tuning support vector machine parameters through implicit differentiation of the optimal solution, directly underpinning the poisoning attack's gradient ascent derivation.
  • Paper: Support-vector networks, Corinna Cortes et al. (1995). This seminal paper defines the formulation and optimization problem of support vector machines, which serves as the direct target system analyzed for training-data vulnerability.
  • Paper: A training algorithm for optimal margin classifiers, B. Boser et al. (1992). This paper establishes the foundational dual optimization and margin-maximization framework of kernel-based support vector machines that the poisoning formulation explicitly exploits.
  • Paper: Stability and Generalization, Olivier Bousquet et al. (2002). This paper formalizes algorithmic stability and quantifies how modifying individual training examples alters learned decision functions, providing essential theoretical context for data-manipulation sensitivity.
Cover for Poisoning Attacks against Support Vector Machines

Abstract

We investigate a family of poisoning attacks against Support Vector Machines (SVM). Such attacks inject specially crafted training data that increases the SVM's test error. Central to the motivation for these attacks is the fact that most learning algorithms assume that their training data comes from a natural or well-behaved distribution. However, this assumption does not generally hold in security-sensitive settings. As we demonstrate, an intelligent adversary can, to some extent, predict the change of the SVM's decision function due to malicious input and use this ability to construct malicious data. The proposed attack uses a gradient ascent strategy in which the gradient is computed based on properties of the SVM's optimal solution. This method can be kernelized and enables the attack to be constructed in the input space even for non-linear kernels. We experimentally demonstrate that our gradient ascent procedure reliably identifies good local maxima of the non-convex validation error surface, which significantly increases the classifier's test error.

Table of Contents

  • 1 Introduction
  • 2 Poisoning attack on SVM
  • 2.1 Main derivation
  • 2.2 Kernelization
  • 2.3 Poisoning Attack Algorithm
  • 3 Experiments
  • 3.1 Artificial data
  • 3.2 Real data
  • 4 Conclusions and Future Work
  • References

Knowls

  1. Knowl 1 — Formulation of SVM Poisoning as Validation Loss Maximization

    model/method

    A poisoning attack against a Support Vector Machine (SVM) is a causative attack where an adversary injects an adversarial training point (xc,yc)∈Rd×{−1,+1}(x_c, y_c) \in \mathbb{R}^d \times \{-1, +1\} into a training dataset Dtr={(xi,yi)}i=1n\mathcal{D}_{tr} = \{(x_i, y_i)\}_{i=1}^n to maximize the classification error of the resulting model on unseen data. The attack point's label ycy_c is chosen and fixed beforehand (defining the attacking class, while the opposite class is the attacked class).

    Using a validation set Dval={(xk,yk)}k=1m\mathcal{D}_{val} = \{(x_k, y_k)\}_{k=1}^m, the adversary's objective is formulated as finding the point xcx_c that maximizes the hinge loss L(xc)L(x_c) incurred on Dval\mathcal{D}_{val} by an SVM trained on Dtr∪{(xc,yc)}\mathcal{D}_{tr} \cup \{(x_c, y_c)\}:

    max⁡xcL(xc)=∑k=1m(1−ykfxc(xk))+=∑k=1m(−gk)+\max_{x_c} L(x_c) = \sum_{k=1}^m (1 - y_k f_{x_c}(x_k))_+ = \sum_{k=1}^m (-g_k)_+

    where (z)+=max⁡(0,z)(z)_+ = \max(0, z), fxc(x)f_{x_c}(x) is the SVM decision function trained on the poisoned dataset Dtr∪{(xc,yc)}\mathcal{D}_{tr} \cup \{(x_c, y_c)\}, and gkg_k is the margin condition for validation point xkx_k:

    gk=∑j∈DtrQkjαj(xc)+Qkc(xc)αc(xc)+ykb(xc)−1g_k = \sum_{j \in \mathcal{D}_{tr}} Q_{kj} \alpha_j(x_c) + Q_{kc}(x_c) \alpha_c(x_c) + y_k b(x_c) - 1

    Here, Qij=yiyjK(xi,xj)Q_{ij} = y_i y_j K(x_i, x_j) is the label-annotated kernel matrix, α(xc)\alpha(x_c) is the vector of SVM dual variables, and b(xc)b(x_c) is the SVM bias term, both of which depend implicitly on xcx_c through the retrained SVM solution.

  2. Knowl 2 — SVM Parameter Sensitivities via KKT Stationarity and Adiabatic Updates

    theoretical result

    The optimal solution of an SVM partition the training samples into margin support vectors ({αi:0<αi<C}\{\alpha_i : 0 < \alpha_i < C\}, set S\mathcal{S}), error support vectors ({αi:αi=C}\{\alpha_i : \alpha_i = C\}, set E\mathcal{E}), and reserve points ({αi:αi=0}\{\alpha_i : \alpha_i = 0\}, set R\mathcal{R}), satisfying the Karush-Kuhn-Tucker (KKT) conditions:

    gi=∑jQijαj+yib−1=0∀i∈S,h=∑jyjαj=0g_i = \sum_{j} Q_{ij} \alpha_j + y_i b - 1 = 0 \quad \forall i \in \mathcal{S}, \qquad h = \sum_j y_j \alpha_j = 0

    Assuming the composition of sets S,E,R\mathcal{S}, \mathcal{E}, \mathcal{R} remains intact under an infinitesimal change in the attack point xcx_c along direction uu (xc(p)=xc(p−1)+tux_c^{(p)} = x_c^{(p-1)} + t u), differentiating the KKT equations for margin support vectors i∈Si \in \mathcal{S} yields the linear system:

    [0ys⊤ysQss][∂b∂u∂αs∂u]=−[0∂Qsc∂u]αc\begin{bmatrix} 0 & y_s^\top \\ y_s & Q_{ss} \end{bmatrix} \begin{bmatrix} \frac{\partial b}{\partial u} \\ \frac{\partial \alpha_s}{\partial u} \end{bmatrix} = -\begin{bmatrix} 0 \\ \frac{\partial Q_{sc}}{\partial u} \end{bmatrix} \alpha_c

    Inverting the matrix using the Sherman-Morrison-Woodbury formula with υ=Qss−1ys\upsilon = Q_{ss}^{-1} y_s and ζ=ys⊤Qss−1ys\zeta = y_s^\top Q_{ss}^{-1} y_s gives closed-form expressions for the sensitivity of the SVM parameters with respect to the attack perturbation direction uu:

    ∂αs∂u=−1ζαc(ζQss−1−υυ⊤)∂Qsc∂u\frac{\partial \alpha_s}{\partial u} = -\frac{1}{\zeta} \alpha_c (\zeta Q_{ss}^{-1} - \upsilon \upsilon^\top) \frac{\partial Q_{sc}}{\partial u}

    ∂b∂u=−1ζαcυ⊤∂Qsc∂u\frac{\partial b}{\partial u} = -\frac{1}{\zeta} \alpha_c \upsilon^\top \frac{\partial Q_{sc}}{\partial u}

    where QssQ_{ss} is the submatrix of label-annotated kernel values among margin support vectors, ysy_s is their label vector, and αc\alpha_c is the dual variable of the attack point.

  3. Knowl 3 — Closed-Form Gradient of SVM Validation Loss for Poisoning Attacks

    equation

    The gradient of the validation hinge loss L(xc)=∑k=1m(−gk)+L(x_c) = \sum_{k=1}^m (-g_k)_+ with respect to the attack direction uu on the set of active validation points (those for which −gk>0-g_k > 0) is given by:

    ∂L∂u=∑k:−gk>0(Mk∂Qsc∂u+∂Qkc∂u)αc\frac{\partial L}{\partial u} = \sum_{k : -g_k > 0} \left( M_k \frac{\partial Q_{sc}}{\partial u} + \frac{\partial Q_{kc}}{\partial u} \right) \alpha_c

    where the vector MkM_k is defined as:

    Mk=−1ζ(Qks(ζQss−1−υυ⊤)+ykυ⊤)M_k = -\frac{1}{\zeta} \left( Q_{ks} (\zeta Q_{ss}^{-1} - \upsilon \upsilon^\top) + y_k \upsilon^\top \right)

    with scalars and vectors defined as:

    • υ=Qss−1ys\upsilon = Q_{ss}^{-1} y_s
    • ζ=ys⊤Qss−1ys\zeta = y_s^\top Q_{ss}^{-1} y_s
    • QksQ_{ks} is the vector of label-annotated kernel entries between validation point xkx_k and the margin support vectors S\mathcal{S}
    • QscQ_{sc} is the vector of label-annotated kernel entries between the margin support vectors and the attack point xcx_c
    • Qkc=ykycK(xk,xc)Q_{kc} = y_k y_c K(x_k, x_c)
    • αc\alpha_c is the dual variable assigned to the attack point in the poisoned SVM model.
  4. Knowl 4 — Kernel Gradients with Respect to Attack Perturbation

    equation

    For an attack point update xc(p)=xc(p−1)+tux_c^{(p)} = x_c^{(p-1)} + t u with step size tt and direction vector uu, the gradient ∂Kic∂u=∂K(xi,xc(p))∂u\frac{\partial K_{ic}}{\partial u} = \frac{\partial K(x_i, x_c^{(p)})}{\partial u} for any training or validation point xix_i takes the following forms for standard kernels:

    • Linear Kernel (K(xi,xc)=xi⊤xcK(x_i, x_c) = x_i^\top x_c): ∂Kic∂u=txi\frac{\partial K_{ic}}{\partial u} = t x_i

    • Polynomial Kernel (K(xi,xc)=(xi⊤xc+R)dK(x_i, x_c) = (x_i^\top x_c + R)^d): ∂Kic∂u=d(xi⊤xc(p)+R)d−1txi≈d(xi⊤xc(p−1)+R)d−1txi\frac{\partial K_{ic}}{\partial u} = d (x_i^\top x_c^{(p)} + R)^{d-1} t x_i \approx d (x_i^\top x_c^{(p-1)} + R)^{d-1} t x_i

    • RBF (Gaussian) Kernel (K(xi,xc)=exp⁡(−γ2∥xi−xc∥2)K(x_i, x_c) = \exp\left(-\frac{\gamma}{2} \|x_i - x_c\|^2\right)): ∂Kic∂u=K(xi,xc(p))γt(xi−xc(p))≈K(xi,xc(p−1))γt(xi−xc(p−1))\frac{\partial K_{ic}}{\partial u} = K(x_i, x_c^{(p)}) \gamma t (x_i - x_c^{(p)}) \approx K(x_i, x_c^{(p-1)}) \gamma t (x_i - x_c^{(p-1)})

    For non-linear kernels, replacing xc(p)x_c^{(p)} with xc(p−1)x_c^{(p-1)} in the gradient expression yields a valid first-order approximation when the step size tt is sufficiently small, enabling optimization directly in the input space.

  5. Knowl 5 — Gradient Ascent Poisoning Attack Algorithm against SVMs

    algorithm

    The algorithm iteratively computes gradient ascent steps in the input space to identify an attack point xcx_c that maximizes validation hinge loss while maintaining the optimal SVM solution at each step via incremental updates.

    Input: Training dataset DtrD_{tr}, validation dataset DvalD_{val}, label of attack point ycy_c, initial attack point xc(0)x_c^{(0)}, step size tt, stopping threshold ϵ\epsilon
    Output: Final attack point xcx_c
    {alpha_i, b} = Learn an SVM on DtrD_{tr}
    p = 0
    repeat
        p = p + 1
        Recompute SVM solution on Dtr∪{(xc(p−1),yc)}D_{tr} \cup \{(x_c^{(p-1)}, y_c)\} using incremental SVM updating
        Compute grad = dL/du on DvalD_{val} according to the validation loss gradient
        Set u = grad / ||grad||_2
        x_c^{(p)} = x_c^{(p-1)} + t * u
    until L(x_c^{(p)}) - L(x_c^{(p-1)}) < \epsilon
    return x_c = x_c^{(p)}

    The attack vector xc(0)x_c^{(0)} is initialized by copying a sample from the attacked class and flipping its label to ycy_c. Step size tt is fixed to a small constant value to avoid breaking the margin support vector partition (S,E,R\mathcal{S}, \mathcal{E}, \mathcal{R}), and incremental SVM updates efficiently recompute {αi,b}\{\alpha_i, b\}.

  6. Knowl 6 — Optimization Landscape and Attack Behavior on 2D Synthetic Gaussian Data

    empirical result

    The gradient ascent attack was evaluated on a 2D synthetic problem with two Gaussian classes: negative class (mean μ−=[−1.5,0]\mu_- = [-1.5, 0], covariance Σ−=0.6I\Sigma_- = 0.6I, label −1-1, attacking class) and positive class (mean μ+=[1.5,0]\mu_+ = [1.5, 0], covariance Σ+=0.6I\Sigma_+ = 0.6I, label +1+1, attacked class), with 25 training points and 500 validation points per class.

    • Linear SVM (C=1C = 1): The error surface over [−5,5]2[-5, 5]^2 is unbounded; constrained to a bounded domain [−4,4]2[-4, 4]^2, the gradient ascent trajectory moves monotonically from the initial flipped blue point deep into the negative region and terminates at the boundary corner of the box, matching the maximum validation hinge loss and classification error.
    • RBF SVM (C=1,γ=0.5C = 1, \gamma = 0.5): The error surface contains non-convex local peaks. The gradient ascent algorithm follows the hinge loss gradient to a local maximum, which coincides with the maximum classification error within the search area.
  7. Knowl 7 — Degradation of MNIST Digit Classification under Single-Point and Multi-Point Poisoning

    empirical result

    The poisoning attack was tested on binary digit classification subproblems from MNIST (7 vs. 1, 9 vs. 8, and 4 vs. 0) with d=784d = 784 normalized pixel features using linear SVMs (C=1C = 1), trained on 100 random samples, validated on 500 samples, and tested on ~2000 samples per class.

    • Single-Point Poisoning: Injecting just a single optimized attack point into a 100-sample training set increased classification error from initial baseline rates of 2–5% up to 15–20% on test data. By comparison, random label flipping (the starting point at iteration 0) only caused minor error increases, showing that gradient optimization is significantly more destructive than random mislabeling.
    • Visual Mimicry: The optimized attack points blurred the attacked digit prototype toward the attacking class shape (e.g., the bottom of a '7' straightened to mimic a '1', the loop of a '9' rounded to mimic an '8', and peripheral noise was added to '4' to resemble '0').
    • Multi-Point Poisoning: Sequential injection of additional attack points caused steady growth in test error, reaching ~25–35% validation error and ~20–30% test error when 8–9% of the training dataset was contaminated.
  8. Knowl 8 — Practical Constraints and Limitations of the SVM Poisoning Attack

    limitation

    The gradient-based SVM poisoning framework has several key limitations:

    1. Step Size Restriction: The analytical gradient derivation assumes that the support vector partition (S,E,R\mathcal{S}, \mathcal{E}, \mathcal{R}) is invariant under the perturbation. This requires using very small step sizes tt, leading to slow convergence and preventing large jumps in input space.
    2. Label Control Assumption: The method assumes the attacker can freely assign arbitrary labels to the injected points. In environments where data is labeled by trusted human oracles (e.g., spam reporting), injected points must satisfy additional semantic constraints to avoid being correctly labeled by the oracle.
    3. Greedy Multi-Point Optimization: Multiple points are injected sequentially via single-point optimization rather than through joint, simultaneous optimization of the entire batch of attack points, which is sub-optimal.
    4. Inverse Feature Mapping: The attack optimizes continuous input feature vectors directly. In domains where features undergo complex, non-smooth, or non-invertible transformations from real-world objects (such as tokenization in spam filtering), generating valid physical attack instances remains challenging.

Coverage note — None was omitted; all key theoretical derivations, algorithm descriptions, experimental setups, quantitative results on synthetic and real datasets, and stated limitations are fully covered.

References

  1. 1.Barreno, Marco, Nelson, Blaine, Sears, Russell, Joseph, Anthony D., and Tygar, J. D. Can machine learning be secure? In Proceedings of the ACM Symposium on Information, Computer and Communications Security (ASIACCS), pp. 16–25, 2006.
  2. 2.Barreno, Marco, Nelson, Blaine, Joseph, Anthony D., and Tygar, J. D. The security of machine learning. Machine Learning, 81(2):121–148, November 2010.
  3. 3.Biggio, Battista, Fumera, Giorgio, and Roli, Fabio. Multiple classifier systems for robust classifier design in adversarial environments. International Journal of Machine Learning and Cybernetics, 1(1):27–41, 2010.
  4. 4.Bolton, Richard J. and Hand, David J. Statistical fraud detection: A review. Journal of Statistical Science, 17(3):235–255, 2002.
  5. 5.Brückner, Michael and Scheffer, Tobias. Nash equilibria of static prediction games. In Advances in Neural Information Processing Systems (NIPS), pp. 171–179. 2009.
  6. 6.Cauwenberghs, Gert and Poggio, Tomaso. Incremental and decremental support vector machine learning. In Leen, T.K., Diettrich, T.G., and Tresp, V. (eds.), Advances in Neural Information Processing Systems 13, pp. 409–415, 2001.
  7. 7.Cova, M., Kruegel, C., and Vigna, G. Detection and analysis of drive-by-download attacks and malicious JavaScript code. In International Conference on World Wide Web (WWW), pp. 281–290, 2010.
  8. 8.Curtsinger, C., Livshits, B., Zorn, B., and Seifert, C. ZOZZLE: Fast and precise in-browser JavaScript malware detection. In USENIX Security Symposium, pp. 33–48, 2011.
  9. 9.Dekel, O., Shamir, O., and Xiao, L. Learning to classify with missing and corrupted features. Machine Learning, 81(2):149–178, 2010.
  10. 10.Forrest, Stephanie, Hofmeyr, Steven A., Somayaji, Anil, and Longstaff, Thomas A. A sense of self for unix processes. In Proceedings of the IEEE Symposium on Security and Privacy, pp. 120–128, 1996.
  11. 11.Globerson, A. and Roweis, S. Nightmare at test time: Robust learning by feature deletion. In International Conference on Machine Learning (ICML), pp. 353–360, 2006.
  12. 12.Kloft, Marius and Laskov, Pavel. Online anomaly detection under adversarial impact. In Proceedings of the 13th International Conference on Artificial Intelligence and Statistics (AISTATS), 2010.
  13. 13.Laskov, Pavel and Šrndić, Nedim. Static detection of malicious JavaScript-bearing PDF documents. In Proceedings of the Annual Computer Security Applications Conference (ACSAC), December 2011.
  14. 14.LeCun, Y., Jackel, L., Bottou, L., Brunot, A., Cortes, C., Denker, J., Drucker, H., Guyon, I., Müller, U., Säckinger, E., Simard, P., and Vapnik, V. Comparison of learning algorithms for handwritten digit recognition. In Int'l Conf. on Artificial Neural Networks, pp. 53–60, 1995.
  15. 15.Lütkepohl, Helmut. Handbook of matrices. John Wiley & Sons, 1996.
  16. 16.Meyer, Tony A. and Whateley, Brendon. SpamBayes: Effective open-source, Bayesian based, email classification system. In Proceedings of the Conference on Email and Anti-Spam (CEAS), July 2004.
  17. 17.Nelson, Blaine, Barreno, Marco, Chi, Fuching Jack, Joseph, Anthony D., Rubinstein, Benjamin I. P., Saini, Udam, Sutton, Charles, Tygar, J. D., and Xia, Kai. Exploiting machine learning to subvert your spam filter. In Proceedings of the 1st USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET), pp. 1–9, 2008.
  18. 18.Rieck, K., Krüger, T., and Dewald, A. Cujo: Efficient detection and prevention of drive-by-download attacks. In Proceedings of the Annual Computer Security Applications Conference (ACSAC), pp. 31–39, 2010.
  19. 19.Rubinstein, Benjamin I. P., Nelson, Blaine, Huang, Ling, Joseph, Anthony D., hon Lau, Shing, Rao, Satish, Taft, Nina, and Tygar, J. D. ANTIDOTE: Understanding and defending against poisoning of anomaly detectors. In Proceedings of the 9th ACM SIGCOMM Conference on Internet Measurement (IMC), pp. 1–14, 2009.
  20. 20.Stolfo, Salvatore J., Hershkop, Shlomo, Wang, Ke, Nimeskern, Olivier, and Hu, Chia-Wei. A behavior-based approach to securing email systems. In Mathematical Methods, Models and Architectures for Computer Networks Security. Springer-Verlag, 2003.
  21. 21.Teo, C.H., Globerson, A., Roweis, S., and Smola, A. Convex learning with invariances. In Advances in Neural Information Proccessing Systems (NIPS), pp. 1489–1496, 2008.

Citation

MLA
Biggio, B., et al. “Poisoning Attacks Against Support Vector Machines”. arXiv, 2012, https://doi.org/10.48550/arxiv.1206.6389.
APA
Biggio, B., Nelson, B., & Laskov, P. (2012). Poisoning Attacks against Support Vector Machines. arXiv. https://doi.org/10.48550/arxiv.1206.6389
Chicago
Biggio, B., B. Nelson, and P. Laskov. 2012. “Poisoning Attacks Against Support Vector Machines”. Preprint, ArXiv. https://doi.org/10.48550/arxiv.1206.6389.
Harvard
Biggio, B., Nelson, B. and Laskov, P. (2012) “Poisoning Attacks against Support Vector Machines”. arXiv. Available at: https://doi.org/10.48550/arxiv.1206.6389.
Vancouver
1. Biggio B, Nelson B, Laskov P (2012) Poisoning Attacks against Support Vector Machines. https://doi.org/10.48550/arxiv.1206.6389

BibTeX

@misc{https://doi.org/10.48550/arxiv.1206.6389,
  doi = {10.48550/ARXIV.1206.6389},
  url = {https://arxiv.org/abs/1206.6389},
  author = {Biggio, Battista and Nelson, Blaine and Laskov, Pavel},
  keywords = {Machine Learning (cs.LG), Cryptography and Security (cs.CR), Machine Learning (stat.ML), FOS: Computer and information sciences, FOS: Computer and information sciences},
  title = {Poisoning Attacks against Support Vector Machines},
  publisher = {arXiv},
  year = {2012},
  copyright = {arXiv.org perpetual, non-exclusive license}
}
Metadata:DOI registry

Source Code

This paper has an official code repository available. Click below to access the source code.

View Repository

Access the Paper

This paper is available from its original source. Click below to access the PDF.

Open PDF

License: Authors