PAPER DIGEST
Most Influential KDD 2004 Paper · 2026-03 edition

Adversarial Classification

Nilesh Dalvi; Pedro Domingos; Sumit Sanghai; Deepak Verma

Venue
ACM SIGKDD Conference (KDD) 2004
Recognition
Most Influential KDD 2004 Paper (Rank No. 4)
Edition
2026-03
Impact factor
9
Certificate ID
5aed625212401899

Abstract

Essentially all data mining algorithms assume that the data-generating process is independent of the data miner's activities. However, in many domains, including spam detection, intrusion detection, fraud detection, surveillance and counter-terrorism, this is far from the case: the data is actively manipulated by an adversary seeking to make the classifier produce false negatives. In these domains, the performance of a classifier can degrade rapidly after it is deployed, as the adversary learns to defeat it. Currently the only solution to this is repeated, manual, <i>ad hoc</i> reconstruction of the classifier. In this paper we develop a formal framework and algorithms for this problem. We view classification as a game between the classifier and the adversary, and produce a classifier that is optimal given the adversary's optimal strategy. Experiments in a spam detection domain show that this approach can greatly outperform a classifier learned in the standard way, and (within the parameters of the problem) automatically adapt the classifier to the adversary's evolving manipulations.

Download PDF certificate