Exploring the Limits of Model-Targeted Indiscriminate Data Poisoning Attacks
Yiwei Lu, Gautam Kamath, Yaoliang Yu
Abstract
Indiscriminate data poisoning attacks aim to decrease a model's test accuracy by injecting a small amount of corrupted training data. Despite significant interest, existing attacks remain relatively ineffective against modern machine learning (ML) architectures. In this work, we introduce the notion of model poisoning reachability as a technical tool to explore the intrinsic limits of data poisoning attacks towards target parameters (i.e., model-targeted attacks). We derive an easily computable threshold to establish and quantify a surprising phase transition phenomenon among popular ML models: data poisoning attacks can achieve certain target parameters only when the poisoning ratio exceeds our threshold. Building on existing parameter corruption attacks and refining the Gradient Canceling attack, we perform extensive experiments to confirm our theoretical findings, test the predictability of our transition threshold, and significantly improve existing indiscriminate data poisoning baselines over a range of datasets and models. Our work highlights the critical role played by the poisoning ratio, and sheds new insights on existing empirical results, attacks and mitigation strategies in data poisoning. Our code is available at https://github.com/watml/plim .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 52a7253d-36c0-4d77-a7c5-85cd63eaad25Cited by top-tier papers9
- Purify Unlearnable Examples via Rate-Constrained Variational AutoencodersYi Yu, Yufei Wang, Song Xia, Wenhan Yang et al.ICML 2024 · 22 citations
- Disguised Copyright Infringement of Latent Diffusion ModelsYiwei Lu, Matthew Y. R. Yang, Zuoqiu Liu, Gautam Kamath et al.ICML 2024 · 10 citations
- BridgePure: Limited Protection Leakage Can Break Black-Box Data ProtectionYihan Wang, Yiwei Lu, Xiao-Shan Gao, Gautam Kamath et al.NeurIPS 2025 · 5 citations
- Distribution Learnability and RobustnessShai Ben-David, Alex Bie, Gautam Kamath, Tosca LechnerNeurIPS 2023 · 5 citations
- Stress-Testing ML Pipelines with Adversarial Data CorruptionJiongli Zhu, Geyang Xu, Felipe Lorenzi, Boris Glavic et al.VLDB 2025 · 2 citations
Builds on12
- Hidden Trigger Backdoor AttacksAniruddha Saha, Akshayvarun Subramanya, Hamed PirsiavashAAAI 2020 · 743 citations
- Back to the Drawing Board: A Critical Evaluation of Poisoning Attacks on Production Federated LearningVirat Shejwalkar, Amir Houmansadr, Peter Kairouz, Daniel RamageS&P 2022 · 302 citations
- Unlearnable Examples: Making Personal Data UnexploitableHanxun Huang, Xingjun Ma, Sarah Monazam Erfani, James Bailey et al.ICLR 2021 · 255 citations
- Adversarial Examples Make Strong PoisonsLiam Fowl, Micah Goldblum, Ping-yeh Chiang, Jonas Geiping et al.NeurIPS 2021 · 185 citations
- Improved Certified Defenses against Data Poisoning with (Deterministic) Finite AggregationWenxiao Wang, Alexander Levine, Soheil FeiziICML 2022 · 68 citations
Related papers
- Model-Targeted Poisoning Attacks with Provable ConvergenceFnu Suya, Saeed Mahloujifar, Anshuman Suri, David Evans et al.ICML 2021 · 52 citations
- Subpopulation Data Poisoning AttacksMatthew Jagielski, Giorgio Severi, Niklas Pousette Harger, Alina OpreaCCS 2021 · 15 citations
- What Distributions are Robust to Indiscriminate Poisoning Attacks for Linear Learners?Fnu Suya, Xiao Zhang, Yuan Tian, David EvansNeurIPS 2023 · 3 citations
- Property Inference from PoisoningSaeed Mahloujifar, Esha Ghosh, Melissa ChaseS&P 2022 · 96 citations
- Witches' Brew: Industrial Scale Data Poisoning via Gradient MatchingJonas Geiping, Liam H. Fowl, W. Ronny Huang, Wojciech Czaja et al.ICLR 2021 · 268 citations
