Theory of Continual Learning Against Data Poisoning Attacks
Yiting Hu, Lingjie Duan
Abstract
Continual learning (CL), where a model is trained on a sequence of data tasks, is increasingly being adopted across key fields such as large language models and image recognition, yet it remains highly vulnerable to data poisoning that triggers learning divergence or severe excess risk. Despite these threats, a principled theoretical foundation in CL for understanding attack and defense remains lacking. In this paper, we develop a theoretical framework to analyze strategic attacks and defenses in regularization-based CL, a cornerstone of recent CL theory. By framing the adversary-defender interaction as an online zero-sum game, we first establish a fundamental performance limit: no defense succeeds when an adversary poisons a linear proportion of tasks by injecting unbounded noise or pattern shifts in regularization-based CL. We then analyze two possibly defensible scenarios: infrequent attacks and bounded noise per attack. For the former regime, we propose a task-to-task verification mechanism to detect data poisoning and reduce cumulative bias for learning convergence. For the latter regime, we derive a robust defense that minimizes the model’s sensitivity to poisoned features, provably accelerating the convergence rate. Extensive experiments on realistic tasks further validate our theoretical results.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0a72862c-1061-43c4-be76-dfe588f0d6d7Builds on13
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Gradient-based Editing of Memory Examples for Online Task-free Continual LearningXisen Jin, Arka Sadhu, Junyi Du, Xiang RenNeurIPS 2021 · 124 citations
- Theory on Forgetting and Generalization of Continual LearningSen Lin, Peizhong Ju, Yingbin Liang, Ness B. ShroffICML 2023 · 74 citations
- Kronecker-Factored Approximate Curvature for Modern Neural Network ArchitecturesRuna Eschenhagen, Alexander Immer, Richard E. Turner, Frank Schneider et al.NeurIPS 2023 · 62 citations
- Continual Learning on Noisy Data Streams via Self-Purified ReplayChris Dongjoo Kim, Jinseo Jeong, Sangwoo Moon, Gunhee KimICCV 2021 · 53 citations
Related papers
- BrainWash: A Poisoning Attack to Forget in Continual LearningAli Abbasi, Parsa Nooralinejad, Hamed Pirsiavash, Soheil KolouriCVPR 2024
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu et al.S&P 2018 · 867 citations
- Adversarial Training for Defense Against Label Poisoning AttacksMelis Ilayda Bal, Volkan Cevher, Michael MuehlebachICLR 2025
- Multi-level Certified Defense Against Poisoning Attacks in Offline Reinforcement LearningShijie Liu, Andrew Craig Cullen, Paul Montague, Sarah Monazam Erfani et al.ICLR 2025
- Exploring the Orthogonality and Linearity of Backdoor AttacksKaiyuan Zhang, Siyuan Cheng, Guangyu Shen, Guanhong Tao et al.S&P 2024 · 11 citations
