Historical milestone · 2004
Adversarial classification
Reviewed through September 18, 2026
2004 · Historical milestone
Adversarial classification
- Era
- 2000s
- Theme
- Safety, security & alignment
- Evidence form
- Modeled classification as a game in which a cost-sensitive adversary modifies examples to evade a learned classifier
- School / paradigm
- Adversarial machine learning
- Institution / context
- University of Washington / IBM
- Researchers
- Nilesh Dalvi; Pedro Domingos; Mausam; Sumit Sanghai; Deepak Verma
Understand
Plain-language record, transferred from the reviewed source module.
Theory or experimental setup. Established that strategic attackers invalidate stationary-data assumptions and require adversary-aware learning.
Result / historical claim. Threat model and feature manipulation were simplified; adaptive attackers and rich models broaden the problem.
Apply
Professional implication, only where the reviewed record states one.
The checked-in record does not state a separate professional application for this entry. The topic page places it in the wider research lineage: Safety, security, and alignment.
Verify
Evidence status, stated limitations, and the external sources this record actually carries.
Evidence form. Modeled classification as a game in which a cost-sensitive adversary modifies examples to evade a learned classifier
Limitation / debate. Jailbreaks, evasion, red teaming, adversarial training, and economic threat modeling.
Source status. The source link below is the verified link our reviewed topic research already carries for this milestone.
Reproduce
A reproduction tutorial is linked only when one exists for this exact record.
A reproduction tutorial is not yet available for this entry. The closest reviewed material is Safety, security, and alignment.
Cite or share
APA-like: This historical record carries a year only, and no author or publisher of record in the checked-in data. An APA reference would have to invent that metadata.
BibTeX: BibTeX requires an author and publication venue. Historical lineage entries store a narrative record and its source link, not structured authorship, so the field would be fabricated.
