Search papers, labs, and topics across Lattice.
This paper introduces a detector-based switched model that enhances the robustness of linear predictive models against stealthy false data injection attacks. By deriving a convex formulation of adversarial risk, the authors incorporate protected features and a hyperparameter to model attack probability, allowing for a quantifiable trade-off between performance on clean and attacked data. Numerical simulations demonstrate that this approach significantly improves performance on partially attacked datasets, even when attack probabilities are misspecified.
Stealthy attacks can now be countered effectively in linear models, improving resilience against adversarial data manipulation.
Predictive models are widely used in many fields, but are vulnerable to false data injection attacks. To address this, detection schemes and adversarial training have been proposed, but such approaches lack guarantees against stealthy attacks. We therefore propose a detector-based switched model, in which optimal attack strategies are stealthy. For linear prediction models, we derive a convex formulation of the resulting adversarial risk. The model incorporates protected features and introduces a hyperparameter modelling attack probability, enabling an explicit performance trade-off between clean and attacked data regimes. Numerical simulations on real and synthetic data show improved performance on partially attacked data, even for misspecified attack probabilities.