Search arXivSearch

arXiv · 2505.03966

Model-Targeted Data Poisoning Attacks against ITS Applications with Provable Convergence

Abstract

The growing reliance of intelligent systems on data makes the systems vulnerable to data poisoning attacks. Such attacks could compromise machine learning or deep learning models by disrupting the input data. Previous studies on data poisoning attacks are subject to specific assumptions, and limited attention is given to learning models with general (equality and inequality) constraints or lacking differentiability. Such learning models are common in practice, especially in Intelligent Transportation Systems (ITS) that involve physical or domain knowledge as specific model constraints. Motivated by ITS applications, this paper formulates a model-target data poisoning attack as a bi-level optimization problem with a constrained lower-level problem, aiming to induce the model solution toward a target solution specified by the adversary by modifying the training data incrementally. As the gradient-based methods fail to solve this optimization problem, we propose to study the Lipschitz continuity property of the model solution, enabling us to calculate the semi-derivative, a one-sided directional derivative, of the solution over data. We leverage semi-derivative descent to solve the bi-level optimization problem, and establish the convergence conditions of the method to any attainable target model. The model and solution method are illustrated with a simulation of a poisoning attack on the lane change detection using SVM.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Xin Wang, Feilong Wang, Yuan Hong, R. Tyrrell Rockafellar, Xuegang, Ban. 2025-05-15. Model-Targeted Data Poisoning Attacks against ITS Applications with Provable Convergence. https://arxiv.org/abs/2505.03966

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

The Riemannian Convex Bundle Method

We introduce the convex bundle method to solve convex, non-smooth optimization problems on Riemannian manifolds of bounded sectional curvature. Each step of our method is based on a model that involves the convex hull of previously collected subgradients, parallelly transported into the current serious iterate. This approach generalizes the dual form of classical bundle subproblems in Euclidean space. We prove that, under mild conditions, the convex bundle method converges to a minimizer. Several numerical examples implemented using Manopt$.$jl illustrate the performance of the proposed method and compare it to the subgradient method, the cyclic proximal point algorithm, as well as the proximal bundle method.

math.OC

Omega-Limit Sets and Input-to-State Stability in Power Grids With Switching Equilibria

This paper studies a power transmission system with both conventional generators (CGs) and distributed energy assets (DEAs) providing frequency control. We consider an operating condition with demand aggregating two dynamic components: one that switches between different values on a finite set, and one that varies smoothly over time. Such dynamic operating conditions may result from protection scheme activations, external cyber-attacks, or due to the integration of dynamic loads, such as data centers. Mathematically, the dynamics of the resulting system are captured by a system that switches between a finite number of vector fields -- or modes--, with each mode having a distinct equilibrium point induced by the demand aggregation. To analyze the stability properties of the resulting switching system, we leverage tools from hybrid dynamic inclusions and the concept of $Ω$-limit sets from sets. Specifically, we characterize a compact set that is semi-globally practically asymptotically stable under the assumption that the switching frequency and load variation rate are sufficiently slow. For arbitrarily fast variations of the load, we use a level-set argument with multiple Lyapunov functions to establish input-to-state stability of a larger set and with respect to the rate of change of the loads. The theoretical results are illustrated via numerical simulations on the IEEE 39-bus test system.

math.OC

Cellular flow control design for mixing based on the least action principle

We consider a novel approach for the enhancement of fluid mixing via pure stirring strategies building upon the Least Action Principle (LAP) for incompressible flows. The LAP is formally analogous to the Benamou--Brenier formulation of optimal transport, but imposes an incompressibility constraint. Our objective is to find a velocity field, generated by Hamiltonian flows, that minimizes the kinetic energy while ensuring that the initial scalar distribution reaches a prescribed degree of mixedness by a finite time. This formulation leads to a ``point-to-set" type of optimization problem which relaxes the requirement on controllability of the system compared to the classic LAP framework. In particular, we assume that the velocity field is induced by a finite set of cellular flows that can be controlled in time. To establish finite time feasibility, we introduce an operator-theoretic switching argument that combines the long-time cellular flow mixing result with the von Neumann alternating-projection theorem. We then leverage the direct method to establish the existence of an optimal solution. Finally, we derive the corresponding optimality conditions for the time-dependent control problem and conduct numerical experiments demonstrating the effectiveness of the proposed control design.

math.OC