{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T15:01:55Z","timestamp":1782313315926,"version":"3.54.5"},"reference-count":45,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2024,3,12]],"date-time":"2024-03-12T00:00:00Z","timestamp":1710201600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"CCF-Huawei Populus Grove Fund","award":["CCF-HuaweiDB2022002"],"award-info":[{"award-number":["CCF-HuaweiDB2022002"]}]},{"DOI":"10.13039\/501100012166","name":"National Key R&D Program of China","doi-asserted-by":"crossref","award":["2022ZD0160501"],"award-info":[{"award-number":["2022ZD0160501"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100001809","name":"Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62372390"],"award-info":[{"award-number":["62372390"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Manag. Data"],"published-print":{"date-parts":[[2024,3,12]]},"abstract":"<jats:p>Despite the promising performance of recent learning-based Index Advisors (IAs), they exhibited the robustness issue when poisoning attacks polluted training data. This paper presents the first attempt to study the robustness of updatable learning-based IAs against poisoning attack, i.e., whether the IAs can maintain robust performance if their training\/updating is disturbed by injecting an extraneous toxic workload. The goal is to provide an opaque-box stress test that is generally effective in evaluating the robustness of different learning-based IAs without using the users' private data.<\/jats:p>\n          <jats:p>There are three challenges, i.e., how to probe \"index preference\" from opaque-box IAs, how to design effective injecting strategies even if the IAs can be fine-tuned, and how to generate queries to meet the specific constraints for IA probing and injecting. The presented stress-test framework PIPA consists of a probing stage, an injecting stage, and a query generator. To address the first challenge, the probing stage estimates the IA's indexing preference by observing its responses to the probing workload. To address the second challenge, the injecting stage injects workloads that spoof the IA to demote the top-ranked indexes in the estimated indexing preference and promote mid-ranked indexes. The stress test is effective because the IA is trapped in a local optimum even after fine-tuning. To address the third challenge, PIPA utilizes IABART (Index Aware BART) to generate queries that can be optimized by building indexes on a given set of indexes. Extensive experiments on different benchmarks against various learning-based IAs demonstrate the effectiveness of PIPA and that existing learning-based IAs are non-robust when faced with even a subtle amount of injected extraneous toxic workloads.<\/jats:p>","DOI":"10.1145\/3639265","type":"journal-article","created":{"date-parts":[[2024,3,26]],"date-time":"2024-03-26T18:51:32Z","timestamp":1711479092000},"page":"1-26","source":"Crossref","is-referenced-by-count":3,"title":["Robustness of Updatable Learning-based Index Advisors against Poisoning Attack"],"prefix":"10.1145","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-9277-3661","authenticated-orcid":false,"given":"Yihang","family":"Zheng","sequence":"first","affiliation":[{"name":"Institute of Artificial Intelligence, Xiamen University, Xiamen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2275-997X","authenticated-orcid":false,"given":"Chen","family":"Lin","sequence":"additional","affiliation":[{"name":"School of Informatics, Xiamen University &amp; Shanghai Artificial Intelligence Laboratory, Xiamen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-3567-9695","authenticated-orcid":false,"given":"Xian","family":"Lyu","sequence":"additional","affiliation":[{"name":"School of Informatics, Xiamen University, Xiamen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2285-7836","authenticated-orcid":false,"given":"Xuanhe","family":"Zhou","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1398-0621","authenticated-orcid":false,"given":"Guoliang","family":"Li","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2437-3341","authenticated-orcid":false,"given":"Tianqing","family":"Wang","sequence":"additional","affiliation":[{"name":"Huawei Company, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,3,26]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-62416-7_19"},{"key":"e_1_2_1_2_1","volume-title":"Machine Learning and Knowledge Discovery in Databases: European Conference, ECML PKDD 2013, Prague, Czech Republic, September 23--27, 2013, Proceedings, Part III 13","author":"Biggio Battista","year":"2013","unstructured":"Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim vS rndi\u0107, Pavel Laskov, Giorgio Giacinto, and Fabio Roli. 2013a. Evasion attacks against machine learning at test time. In Machine Learning and Knowledge Discovery in Databases: European Conference, ECML PKDD 2013, Prague, Czech Republic, September 23--27, 2013, Proceedings, Part III 13. Springer, 387--402."},{"key":"e_1_2_1_3_1","volume-title":"Poisoning attacks against support vector machines. arXiv preprint arXiv:1206.6389","author":"Biggio Battista","year":"2012","unstructured":"Battista Biggio, Blaine Nelson, and Pavel Laskov. 2012. Poisoning attacks against support vector machines. arXiv preprint arXiv:1206.6389 (2012)."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2517312.2517321"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCIAIG.2012.2186810"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1066157.1066184"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2006.190"},{"key":"e_1_2_1_8_1","volume-title":"VLDB","volume":"97","author":"Chaudhuri Surajit","year":"1997","unstructured":"Surajit Chaudhuri and Vivek R Narasayya. 1997. An efficient, cost-driven index selection tool for Microsoft SQL server. In VLDB, Vol. 97. San Francisco, 146--155."},{"key":"e_1_2_1_9_1","volume-title":"Wild patterns reloaded: A survey of machine learning security against training data poisoning. arXiv preprint arXiv:2205.01992","author":"Cin\u00e0 Antonio Emanuele","year":"2022","unstructured":"Antonio Emanuele Cin\u00e0, Kathrin Grosse, Ambra Demontis, Sebastiano Vascon, Werner Zellinger, Bernhard A Moser, Alina Oprea, Battista Biggio, Marcello Pelillo, and Fabio Roli. 2022. Wild patterns reloaded: A survey of machine learning security against training data poisoning. arXiv preprint arXiv:2205.01992 (2022)."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACOMP50827.2020.00010"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3299869.3324957"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380072"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3511808.3557163"},{"key":"e_1_2_1_14_1","volume-title":"Qi Li, Bin Liu, and Mingwei Xu.","author":"Huang Hai","year":"2021","unstructured":"Hai Huang, Jiaming Mu, Neil Zhenqiang Gong, Qi Li, Bin Liu, and Mingwei Xu. 2021. Data poisoning attacks to deep learning based recommender systems. arXiv preprint arXiv:2101.02644 (2021)."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00300"},{"key":"e_1_2_1_17_1","volume-title":"The Price of Tailoring the Index to Your Data: Poisoning Attacks on Learned Index Structures. arXiv preprint arXiv:2008.00297","author":"Kornaropoulos Evgenios M","year":"2020","unstructured":"Evgenios M Kornaropoulos, Silei Ren, and Roberto Tamassia. 2020. The Price of Tailoring the Index to Your Data: Poisoning Attacks on Learned Index Structures. arXiv preprint arXiv:2008.00297 (2020)."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.14778\/3407790.3407832"},{"key":"e_1_2_1_19_1","volume-title":"SWIRL: Selection of Workload-aware Indexes using Reinforcement Learning.. In EDBT. 2--155.","author":"Kossmann Jan","year":"2022","unstructured":"Jan Kossmann, Alexander Kastius, and Rainer Schlosser. 2022. SWIRL: Selection of Workload-aware Indexes using Reinforcement Learning.. In EDBT. 2--155."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3340531.3412106"},{"key":"e_1_2_1_21_1","volume-title":"Bart: Denoising sequence-to-sequence pre-training for natural language generation, translation, and comprehension. arXiv preprint arXiv:1910.13461","author":"Lewis Mike","year":"2019","unstructured":"Mike Lewis, Yinhan Liu, Naman Goyal, Marjan Ghazvininejad, Abdelrahman Mohamed, Omer Levy, Ves Stoyanov, and Luke Zettlemoyer. 2019. Bart: Denoising sequence-to-sequence pre-training for natural language generation, translation, and comprehension. arXiv preprint arXiv:1910.13461 (2019)."},{"key":"e_1_2_1_22_1","volume-title":"A diversity-promoting objective function for neural conversation models. arXiv preprint arXiv:1510.03055","author":"Li Jiwei","year":"2015","unstructured":"Jiwei Li, Michel Galley, Chris Brockett, Jianfeng Gao, and Bill Dolan. 2015. A diversity-promoting objective function for neural conversation models. arXiv preprint arXiv:1510.03055 (2015)."},{"key":"e_1_2_1_23_1","first-page":"12400","article-title":"Provably efficient black-box action poisoning attacks against reinforcement learning","volume":"34","author":"Liu Guanlin","year":"2021","unstructured":"Guanlin Liu and Lifeng Lai. 2021. Provably efficient black-box action poisoning attacks against reinforcement learning. Advances in Neural Information Processing Systems, Vol. 34 (2021), 12400--12410.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_2_1_24_1","volume-title":"Advances in Neural Information Processing Systems","volume":"32","author":"Ma Yuzhe","year":"2019","unstructured":"Yuzhe Ma, Xuezhou Zhang, Wen Sun, and Jerry Zhu. 2019. Policy poisoning in batch reinforcement learning and control. Advances in Neural Information Processing Systems, Vol. 32 (2019)."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1376616.1376668"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE51399.2021.00058"},{"key":"e_1_2_1_27_1","volume-title":"International Conference on Machine Learning. PMLR, 7974--7984","author":"Rakhsha Amin","year":"2020","unstructured":"Amin Rakhsha, Goran Radanovic, Rati Devidze, Xiaojin Zhu, and Adish Singla. 2020. Policy teaching via environment poisoning: Training-time adversarial attacks against reinforcement learning. In International Conference on Machine Learning. PMLR, 7974--7984."},{"key":"e_1_2_1_28_1","volume-title":"Reward poisoning in reinforcement learning: Attacks against unknown learners in unknown environments. arXiv preprint arXiv:2102.08492","author":"Rakhsha Amin","year":"2021","unstructured":"Amin Rakhsha, Xuezhou Zhang, Xiaojin Zhu, and Adish Singla. 2021. Reward poisoning in reinforcement learning: Attacks against unknown learners in unknown environments. arXiv preprint arXiv:2102.08492 (2021)."},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3410566.3410603"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDEW49219.2020.00035"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2019.00113"},{"key":"e_1_2_1_32_1","unstructured":"Andreas Seltenreich Bo Tang and Sjoerd Mullender. 2020. SQLsmith: Score list."},{"key":"e_1_2_1_33_1","volume-title":"Felix Martin Schuhknecht, and Jens Dittrich","author":"Sharma Ankur","year":"2018","unstructured":"Ankur Sharma, Felix Martin Schuhknecht, and Jens Dittrich. 2018. The case for automatic database administration using deep reinforcement learning. arXiv preprint arXiv:1801.05643 (2018)."},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3514221.3526152"},{"key":"e_1_2_1_35_1","volume-title":"VLDB","volume":"98","author":"Slutz Donald R","year":"1998","unstructured":"Donald R Slutz. 1998. Massive stochastic testing of SQL. In VLDB, Vol. 98. Citeseer, 618--622."},{"key":"e_1_2_1_36_1","volume-title":"Vulnerability-aware poisoning mechanism for online rl with unknown dynamics. arXiv preprint arXiv:2009.00774","author":"Sun Yanchao","year":"2020","unstructured":"Yanchao Sun, Da Huo, and Furong Huang. 2020. Vulnerability-aware poisoning mechanism for online rl with unknown dynamics. arXiv preprint arXiv:2009.00774 (2020)."},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00402"},{"key":"e_1_2_1_38_1","volume-title":"Concealed data poisoning attacks on nlp models. arXiv preprint arXiv:2010.12563","author":"Wallace Eric","year":"2020","unstructured":"Eric Wallace, Tony Z Zhao, Shi Feng, and Sameer Singh. 2020. Concealed data poisoning attacks on nlp models. arXiv preprint arXiv:2010.12563 (2020)."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4613-1881-1_41"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3514221.3526128"},{"key":"e_1_2_1_41_1","volume-title":"Generative poisoning attack method against neural networks. arXiv preprint arXiv:1703.01340","author":"Yang Chaofei","year":"2017","unstructured":"Chaofei Yang, Qing Wu, Hai Li, and Yiran Chen. 2017a. Generative poisoning attack method against neural networks. arXiv preprint arXiv:1703.01340 (2017)."},{"key":"e_1_2_1_42_1","volume-title":"Generative poisoning attack method against neural networks. arXiv preprint arXiv:1703.01340","author":"Yang Chaofei","year":"2017","unstructured":"Chaofei Yang, Qing Wu, Hai Li, and Yiran Chen. 2017b. Generative poisoning attack method against neural networks. arXiv preprint arXiv:1703.01340 (2017)."},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3514221.3526155"},{"key":"e_1_2_1_44_1","volume-title":"International Conference on Machine Learning. PMLR, 11225--11234","author":"Zhang Xuezhou","year":"2020","unstructured":"Xuezhou Zhang, Yuzhe Ma, Adish Singla, and Xiaojin Zhu. 2020. Adaptive reward-poisoning attacks against reinforcement learning. In International Conference on Machine Learning. PMLR, 11225--11234."},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE53745.2022.00210"}],"container-title":["Proceedings of the ACM on Management of Data"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3639265","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3639265","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T15:12:03Z","timestamp":1755789123000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3639265"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,3,12]]},"references-count":45,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2024,3,12]]}},"alternative-id":["10.1145\/3639265"],"URL":"https:\/\/doi.org\/10.1145\/3639265","relation":{},"ISSN":["2836-6573"],"issn-type":[{"value":"2836-6573","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,3,12]]}}}