Poisoning Generative Replay in Continual Learning to Promote Forgetting
Siteng Kang, Zhan Shi, Xinhua Zhang
Abstract
Generative models have grown into the workhorse of many state-of-the-art machine learning methods. However, their vulnerability under poisoning attacks has been largely understudied. In this work, we investigate this issue in the context of continual learning, where generative replayers are utilized to tackle catastrophic forgetting. By developing a novel customization of dirty-label input-aware backdoors to the online setting, our attacker manages to stealthily promote forgetting while retaining high accuracy at the current task and sustaining strong defenders. Our approach taps into an intriguing property of generative models, namely that they cannot well capture inputdependent triggers. Experiments on four standard datasets corroborate the poisoner's effectiveness.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 89886ae1-a414-430b-80a5-51e3ff94da62Cited by top-tier papers4
- BackdoorIndicator: Leveraging OOD Data for Proactive Backdoor Detection in Federated LearningSongze Li, Yanbo DaiUSENIX Security 2024 · 31 citations
- Attack on Prompt: Backdoor Attack in Prompt-Based Continual LearningTrang Nguyen, Anh Tran, Nhat HoAAAI 2025 · 3 citations
- Persistent Backdoor Attacks in Continual LearningZhen Guo, Abhinav Kumar, Reza TouraniUSENIX Security 2025
- BrainWash: A Poisoning Attack to Forget in Continual LearningAli Abbasi, Parsa Nooralinejad, Hamed Pirsiavash, Soheil KolouriCVPR 2024
Builds on10
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li et al.S&P 2019 · 1,801 citations
- Trojaning Attack on Neural NetworksYingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee et al.NDSS 2018 · 1,377 citations
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu et al.S&P 2018 · 867 citations
- Input-Aware Dynamic Backdoor AttackTuan Anh Nguyen, Anh Tuan TranNeurIPS 2020 · 601 citations
- GAN-Leaks: A Taxonomy of Membership Inference Attacks against Generative ModelsDingfan Chen, Ning Yu, Yang Zhang, Mario FritzCCS 2020 · 278 citations
Related papers
- Persistent Backdoor Attacks Under Continual Fine-Tuning of LLMsJing Cui, Yufei Han, Jianbin Jiao, Junge ZhangAAAI 2026
- Narcissus: A Practical Clean-Label Backdoor Attack with Limited InformationYi Zeng, Minzhou Pan, Hoang Anh Just, Lingjuan Lyu et al.CCS 2023 · 170 citations
- DEFEAT: Deep Hidden Feature Backdoor Attacks by Imperceptible Perturbation and Latent Representation ConstraintsZhendong Zhao, Xiaojun Chen, Yuexin Xuan, Ye Dong et al.CVPR 2022 · 72 citations
- Oblivion: Poisoning Federated Learning by Inducing Catastrophic ForgettingChen Zhang, Boyang Zhou, Zhiqiang He, Zeyuan Liu et al.INFOCOM 2023 · 4 citations
- Breaking the Stealth-Potency Trade-off in Clean-Image Backdoors with Generative Trigger OptimizationBinyan Xu, Fan Yang, Di Tang, Xilin Dai et al.AAAI 2026 · 1 citation
