Understanding the Limits of Unsupervised Domain Adaptation via Data Poisoning
Akshay Mehra, Bhavya Kailkhura, Pin-Yu Chen, Jihun Hamm
Abstract
Unsupervised domain adaptation (UDA) enables cross-domain learning without target domain labels by transferring knowledge from a labeled source domain whose distribution differs from that of the target. However, UDA is not always successful and several accounts of `negative transfer' have been reported in the literature. In this work, we prove a simple lower bound on the target domain error that complements the existing upper bound. Our bound shows the insufficiency of minimizing source domain error and marginal distribution mismatch for a guaranteed reduction in the target domain error, due to the possible increase of induced labeling function mismatch. This insufficiency is further illustrated through simple distributions for which the same UDA approach succeeds, fails, and may succeed or fail with an equal chance. Motivated from this, we propose novel data poisoning attacks to fool UDA methods into learning representations that produce large target domain errors. We evaluate the effect of these attacks on popular UDA methods using benchmark datasets where they have been previously shown to be successful. Our results show that poisoning can significantly decrease the target domain accuracy, dropping it to almost 0% in some cases, with the addition of only 10% poisoned data in the source domain. The failure of these UDA methods demonstrates their limitations at guaranteeing cross-domain generalization consistent with our lower bound. Thus, evaluating UDA methods in adversarial settings such as data poisoning provides a better sense of their robustness to data distributions unfavorable for UDA.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dc631725-9345-4346-b2df-75be5e9d9cccCited by top-tier papers4
- Better Safe Than Sorry: Preventing Delusive Adversaries with Adversarial TrainingLue Tao, Lei Feng, Jinfeng Yi, Sheng-Jun Huang et al.NeurIPS 2021 · 90 citations
- Understanding the Transferability of Representations via Task-RelatednessAkshay Mehra, Yunbei Zhang, Jihun HammNeurIPS 2024 · 13 citations
- Uncovering Adversarial Risks of Test-Time AdaptationTong Wu, Feiran Jia, Xiangyu Qi, Jiachen T. Wang et al.ICML 2023 · 12 citations
- Domain Adaptation with Adaptive -Divergence: Tighter Variational Representation and Generalization BoundsZhe Cheng, Fode Zhang, Yifan Zhu, Lingrui Wang et al.ICML 2026
Builds on4
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu et al.S&P 2018 · 867 citations
- MetaPoison: Practical General-purpose Clean-label Data PoisoningW. Ronny Huang, Jonas Geiping, Liam Fowl, Gavin Taylor et al.NeurIPS 2020 · 242 citations
- Domain Adaptation with Conditional Distribution Matching and Generalized Label ShiftRemi Tachet des Combes, Han Zhao, Yu-Xiang Wang, Geoffrey J. GordonNeurIPS 2020 · 231 citations
- How Robust Are Randomized Smoothing Based Defenses to Data Poisoning?Akshay Mehra, Bhavya Kailkhura, Pin-Yu Chen, Jihun HammCVPR 2021
Related papers
- Indirect Invisible Poisoning Attacks on Domain AdaptationJun Wu, Jingrui HeKDD 2021 · 15 citations
- Distributionally Robust Classification for Multi-source Unsupervised Domain AdaptationSeonghwi Kim, Sungho Jo, Wooseok Ha, Minwoo ChaeICLR 2026 · 4 citations
- CASUAL: Conditional Support Alignment for Domain Adaptation with Label ShiftAnh T. Nguyen, Lam Tran, Anh Tong, Tuan-Duy H. Nguyen et al.AAAI 2025 · 3 citations
- Information-Theoretic Analysis of Unsupervised Domain AdaptationZiqiao Wang, Yongyi MaoICLR 2023 · 4 citations
- Unknown-Aware Domain Adversarial Learning for Open-Set Domain AdaptationJoonHo Jang, Byeonghu Na, DongHyeok Shin, Mingi Ji et al.NeurIPS 2022 · 85 citations
