Back to Basics: Strengthening Targeted Data Poisoning through Sample Selection
Abstract
Targeted data poisoning attacks manipulate a small subset of training samples to induce a model to misclassify a specific test example as an attacker-chosen class. Existing attacks primarily focus on optimizing perturbations over a predefined set of training samples, which is often selected randomly, while paying limited attention to which samples should be poisoned. In this paper, we show that sample selection can substantially affect attack effectiveness, particularly when the poisoning budget is limited. To understand what makes a training sample effective for poisoning, we incorporate sample selection into the standard bilevel formulation of targeted data poisoning. Our analysis identifies two key characteristics of effective poisoning samples: low model confidence and high representation-space similarity to the target. Motivated by these insights, we propose BASIS (Boundary-Aware Selection Informed by Similarity), a lightweight plug-and-play sample selection method that strengthens existing poisoning attacks without modifying their perturbation optimization. Experiments across multiple attack methods and poisoning budgets demonstrate that BASIS consistently improves attack success rates through sample selection alone, with particularly substantial gains under small poisoning budgets.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.