Poisoning Attack in Machine Learning Based Invalid Ad Traffic Detection
摘要
Along with the growing market of mobile advertising, click farm that leverages large-scale fake devices to conduct ad fraud is becoming a major threats against mobile advertising. These click farms evolve to mimic the usage patterns of normal users, which makes traditional rule-based detection methods unable to tackle with the new threats. To defeat these attacks, machine leaning-based (ML-based) approaches are adopted as a data driven method to detect invalid traffic from click farms by both industry and academia. However, the vulnerability of ML-based detection methods is still an open problem under the adversarial situation. In this study, we present a first study on the poisoning attack in ML-based ad fraud detection. By injecting poison samples to the training set, we demonstrate the effectiveness and concealment of the poisoning attacks under two machine learning models, Gradient Boosting Decision Tree (GBDT) and Deep Neural Networks (DNNs). We conduct experiments with a real-world data set, the results show that the poisoning attack can achieve 0.85 and 0.91 attack success rate for GBDT and DNNs respectively.