Deception by Omission: Using Adversarial Missingness to Poison Causal Structure Learning
Deniz Koyuncu, Alex Gittens, Bülent Yener, Moti Yung
Abstract
Causality-informed machine learning has been proposed as an avenue for achieving many of the goals of modern machine learning, from ensuring generalization under domain shifts to attaining fairness, robustness, and interpretability. A key component of causal machine learning is the inference of causal structures from observational data; in practice, this data may be incompletely observed. Prior work has demonstrated that adversarial perturbations of completely observed training data may be used to force the learning of inaccurate causal structural models (SCMs). However, when the data can be audited for correctness (e.g., it is cryptographically signed by its source), this adversarial mechanism is invalidated. This work introduces a novel attack methodology wherein the adversary deceptively omits a portion of the true training data to bias the learned causal structures in a desired manner (under strong signed sample input validation, this behavior seems to be the only strategy available to the adversary). Under this model, theoretically sound attack mechanisms are derived for the case of arbitrary SCMs, and a sample-efficient learning-based heuristic is given. Experimental validation of these approaches on real and synthetic data sets demonstrates the effectiveness of adversarial missingness attacks at deceiving popular causal structure learning algorithms.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6fc3bd56-ac25-4e2a-b8d3-778666787badCited by top-tier papers2
- Fair Graph Machine Learning under Adversarial Missingness ProcessesDebolina Halder Lina, Arlei SilvaICLR 2026
- Exploiting Missing Data Remediation Strategies Using Adversarial Missingness AttacksDeniz Koyuncu, Alex Gittens, Bülent Yener, Moti YungAAAI 2026
Builds on3
- On the Role of Sparsity and DAG Constraints for Learning Linear DAGsIgnavier Ng, AmirEmad Ghassami, Kun ZhangNeurIPS 2020 · 306 citations
- Causal Discovery with Reinforcement LearningShengyu Zhu, Ignavier Ng, Zhitang ChenICLR 2020 · 285 citations
- MissDAG: Causal Discovery in the Presence of Missing Data with Continuous Additive Noise ModelsErdun Gao, Ignavier Ng, Mingming Gong, Li Shen et al.NeurIPS 2022 · 36 citations
Related papers
- Alleviating Privacy Attacks via Causal LearningShruti Tople, Amit Sharma, Aditya NoriICML 2020 · 35 citations
- Membership Inference Attacks and Generalization: A Causal PerspectiveTeodora Baluta, Shiqi Shen, S. Hitarth, Shruti Tople et al.CCS 2022 · 16 citations
- Amortized Inference for Causal Structure LearningLars Lorch, Scott Sussex, Jonas Rothfuss, Andreas Krause et al.NeurIPS 2022 · 118 citations
- CausalProfiler: Generating Synthetic Benchmarks for Rigorous and Transparent Evaluation of Causal Machine LearningPanayiotis Panayiotou, Audrey Poinsot, Alessandro Leite, Nicolas CHESNEAU et al.ICML 2026
- Counterfactual Fairness with Imperfect Causal GraphsCong Su, Qiaoyu Tan, Carlotta Domeniconi, Lizhen Cui et al.AAAI 2026
