PTTA: Purifying Malicious Samples for Test-Time Model Adaptation
Jing Ma, Hanlin Li, Xiang Xiang
Abstract
Test-Time Adaptation (TTA) enables deep neural networks to adapt to arbitrary distributions during inference. Existing TTA algorithms generally tend to select benign samples that help achieve robust online prediction and stable self-training. Although malicious samples that would undermine the model's optimization should be filtered out, it also leads to a waste of test data. To alleviate this issue, we focus on how to make full use of the malicious test samples for TTA by transforming them into benign ones, and propose a plug-and-play method, PTTA. The core of our solution lies in the purification strategy, which retrieves benign samples having opposite effects on the objective function to perform Mixup with malicious samples, based on a saliency indicator for encoding benign and malicious data. This strategy results in effective utilization of the information in malicious samples and an improvement of the models' online test accuracy. In this way, we can directly apply the purification loss to existing TTA algorithms without the need to carefully adjust the sample selection threshold. Extensive experiments on four types of TTA tasks as well as classification, segmentation, and adversarial defense demonstrate the effectiveness of our method. Code is available at https: //github.com/HAIV-Lab/PTTA.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Decoupled Entropy MinimizationJing Ma, Hanlin Li, Xiang XiangNeurIPS 2025 · 2 citations
- Blocking the Leakage: Manifold-Aware Gradient Projection for Long-Horizon Test-Time AdaptationHaoyu Xiong, Chengchao Wang, ZhongQiang Wang, Huang He et al.ICML 2026
Builds on17
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- The Many Faces of Robustness: A Critical Analysis of Out-of-Distribution GeneralizationDan Hendrycks, Steven Basart, Norman Mu, Saurav Kadavath et al.ICCV 2021 · 2,294 citations
- Adversarially Robust DistillationMicah Goldblum, Liam Fowl, Soheil Feizi, Tom GoldsteinAAAI 2020 · 258 citations
- Entropy is not Enough for Test-Time Adaptation: From the Perspective of Disentangled FactorsJonghyun Lee, Dahuin Jung, Saehyung Lee, Junsung Park et al.ICLR 2024 · 106 citations
- Efficient Test-Time Adaptation for Super-Resolution with Second-Order Degradation and ReconstructionZeshuai Deng, Zhuokun Chen, Shuaicheng Niu, Thomas H. Li et al.NeurIPS 2023 · 37 citations
Related papers
- On the Adversarial Risk of Test Time Adaptation: An Investigation into Realistic Test-Time Data PoisoningYongyi Su, Yushu Li, Nanqing Liu, Kui Jia et al.ICLR 2025
- Uncovering Adversarial Risks of Test-Time AdaptationTong Wu, Feiran Jia, Xiangyu Qi, Jiachen T. Wang et al.ICML 2023 · 12 citations
- Test-Time Poisoning Attacks Against Test-Time Adaptation ModelsTianshuo Cong, Xinlei He, Yun Shen, Yang ZhangS&P 2024 · 11 citations
- On the Adversarial Vulnerability of Label-Free Test-Time AdaptationShahriar Rifat, Jonathan D. Ashdown, Michael J. De Lucia, Ananthram Swami et al.ICLR 2025
- Online Adversarial Purification based on Self-supervised LearningChanghao Shi, Chester Holtz, Gal MishneICLR 2021 · 63 citations
