Historical milestone · 2004

    Adversarial classification

    Reviewed through September 18, 2026

    2004 · Historical milestone

    Adversarial classification

    Era
    2000s
    Theme
    Safety, security & alignment
    Evidence form
    Modeled classification as a game in which a cost-sensitive adversary modifies examples to evade a learned classifier
    School / paradigm
    Adversarial machine learning
    Institution / context
    University of Washington / IBM
    Researchers
    Nilesh Dalvi; Pedro Domingos; Mausam; Sumit Sanghai; Deepak Verma

    Understand

    Plain-language record, transferred from the reviewed source module.

    Theory or experimental setup. Established that strategic attackers invalidate stationary-data assumptions and require adversary-aware learning.

    Result / historical claim. Threat model and feature manipulation were simplified; adaptive attackers and rich models broaden the problem.

    Apply

    Professional implication, only where the reviewed record states one.

    The checked-in record does not state a separate professional application for this entry. The topic page places it in the wider research lineage: Safety, security, and alignment.

    Verify

    Evidence status, stated limitations, and the external sources this record actually carries.

    Evidence form. Modeled classification as a game in which a cost-sensitive adversary modifies examples to evade a learned classifier

    Limitation / debate. Jailbreaks, evasion, red teaming, adversarial training, and economic threat modeling.

    Source status. The source link below is the verified link our reviewed topic research already carries for this milestone.

    Reproduce

    A reproduction tutorial is linked only when one exists for this exact record.

    A reproduction tutorial is not yet available for this entry. The closest reviewed material is Safety, security, and alignment.

    Cite or share

    APA-like: This historical record carries a year only, and no author or publisher of record in the checked-in data. An APA reference would have to invent that metadata.

    BibTeX: BibTeX requires an author and publication venue. Historical lineage entries store a narrative record and its source link, not structured authorship, so the field would be fabricated.

    Related