Data Poisoning Attacks against Conformal Prediction
Yangyi Li, Aobo Chen, Wei Qian, Chenxu Zhao, Divya Lidder, Mengdi Huai
Abstract
The efficient and theoretically sound uncertainty quantification is crucial for building trust in deep learning models. This has spurred a growing interest in conformal prediction (CP), a powerful technique that provides a model-agnostic and distribution-free method for obtaining conformal prediction sets with theoretical guarantees. However, the vulnerabilities of such CP methods with regard to dedicated data poisoning attacks have not been studied previously. To bridge this gap, for the first time, we in this paper propose a new class of black-box data poisoning attacks against CP, where the adversary aims to cause the desired manipulations of some specific examples' prediction uncertainty results (instead of misclassifications). Additionally, we design novel optimization frameworks for our proposed attacks. Further, we conduct extensive experiments to validate the effectiveness of our attacks on various settings (e.g., the full and split CP settings). Notably, our extensive experiments show that our attacks are more effective in manipulating uncertainty results than traditional poisoning attacks that aim at inducing misclassifications, and existing defenses against conventional attacks are ineffective against our proposed attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c260e2c2-339e-4a89-a093-52e244974decCited by top-tier papers4
- Membership Inference Attacks With False Discovery Rate ControlChenxu Zhao, Wei Qian, Aobo Chen, Mengdi HuaiICCV 2025 · 2 citations
- Provably Reliable Conformal Prediction Sets in the Presence of Data PoisoningYan Scholten, Stephan GünnemannICLR 2025
- Efficient Robust Conformal Prediction via Lipschitz-Bounded NetworksThomas Massena, Léo Andéol, Thibaut Boissin, Franck Mamalet et al.ICML 2025
- Enhancing Adversarial Robustness with Conformal Prediction: A Framework for Guaranteed Model ReliabilityJie Bao, Chuangyin Dang, Rui Luo, Hanwei Zhang et al.ICML 2025
Builds on35
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Sharpness-aware Minimization for Efficiently Improving GeneralizationPierre Foret, Ariel Kleiner, Hossein Mobahi, Behnam NeyshaburICLR 2021 · 1,861 citations
- Classification with Valid and Adaptive CoverageYaniv Romano, Matteo Sesia, Emmanuel J. CandèsNeurIPS 2020 · 586 citations
- Anti-Backdoor Learning: Training Clean Models on Poisoned DataYige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu et al.NeurIPS 2021 · 503 citations
- Witches' Brew: Industrial Scale Data Poisoning via Gradient MatchingJonas Geiping, Liam H. Fowl, W. Ronny Huang, Wojciech Czaja et al.ICLR 2021 · 268 citations
Related papers
- Ensemble Conformal Predictor (EnCP): A New Conformal Predictor with Robustness Guarantees Against Data Poisoning AttacksYuxin Yang, Qiang Li, Runyang Feng, Liren Shan et al.S&P 2026
- Robust Yet Efficient Conformal Prediction SetsSoroush H. Zargarbashi, Mohammad Sadegh Akhondzadeh, Aleksandar BojchevskiICML 2024 · 19 citations
- Verifiably Robust Conformal PredictionLinus Jeary, Tom Kuipers, Mehran Hosseini, Nicola PaolettiNeurIPS 2024 · 16 citations
- Direct Prediction Set Minimization via Bilevel Conformal Classifier TrainingYuanjie Shi, Hooman Shahrokhi, Xuesong Jia, Xiongzhi Chen et al.ICML 2025
- Adversarially Robust Conformal PredictionAsaf Gendler, Tsui-Wei Weng, Luca Daniel, Yaniv RomanoICLR 2022 · 51 citations
