Search⌘ K
AI Features

Poisoning Budgets and Realistic Attacker Constraints

Explore how training data pipelines limit attacker control through poisoning budgets and constraints. Understand how these constraints impact attacker capabilities, forcing trade-offs between volume, control, and stealth. This lesson helps you assess attack feasibility by matching attacker influence to pipeline defenses, enabling you to evaluate realistic training-time poisoning risks in machine learning systems.

A training pipeline does not accept data from the internet as a whole. It accepts records through specific ingestion channels like a user upload endpoint, a vendor drop, or a labeling queue, and each channel limits what an attacker can realistically change.

A poisoning budget is the attacker’s practical influence over that pipeline. It includes how many training examples they can affect, what fields they can control for those examples, like pixels and labels, and when their influence applies, such as a one-day window versus a steady trickle.

To make that concrete, look at how a record moves through the pipeline below, from three ingestion channels through validation, ...