Indirect Invisible Poisoning Attacks on Domain Adaptation
Jun Wu, Jingrui He
摘要
Unsupervised domain adaptation has been successfully applied across multiple high-impact applications, since it improves the generalization performance of a learning algorithm when the source and target domains are related. However, the adversarial vulnerability of domain adaptation models has largely been neglected. Most existing unsupervised domain adaptation algorithms might be easily fooled by an adversary, resulting in deteriorated prediction performance on the target domain, when transferring the knowledge from a maliciously manipulated source domain.
To demonstrate the adversarial vulnerability of existing domain adaptation techniques, in this paper, we propose a generic data poisoning attack framework named I2Attack for domain adaptation with the following properties: (1) perceptibly unnoticeable: all the poisoned inputs are natural-looking; (2) adversarially indirect: only source examples are maliciously manipulated; (3) algorithmically invisible: both source classification error and marginal domain discrepancy between source and target domains will not increase. Specifically, it aims to degrade the overall prediction performance on the target domain by maximizing the label-informed domain discrepancy over both input feature space and class-label space between source and target domains. Within this framework, a family of practical poisoning attacks are presented to fool the existing domain adaptation algorithms associated with different discrepancy measures. Extensive experiments on various domain adaptation benchmarks confirm the effectiveness and computational efficiency of our proposed I2Attack framework.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Non-IID Transfer Learning on GraphsJun Wu, Jingrui He, Elizabeth A. AinsworthAAAI 2023 · 被引用 63 次
- Contrastive Learning with Complex HeterogeneityLecheng Zheng, Jinjun Xiong, Yada Zhu, Jingrui HeKDD 2022 · 被引用 29 次
- Distribution-Informed Neural Networks for Domain Adaptation RegressionJun Wu, Jingrui He, Sheng Wang, Kaiyu Guan 等NeurIPS 2022 · 被引用 23 次
- Personalized Federated Learning with Parameter PropagationJun Wu, Wenxuan Bao, Elizabeth A. Ainsworth, Jingrui HeKDD 2023 · 被引用 17 次
- Uncovering Adversarial Risks of Test-Time AdaptationTong Wu, Feiran Jia, Xiangyu Qi, Jiachen T. Wang 等ICML 2023 · 被引用 12 次
它引用的顶会 Paper7
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Adversarially robust transfer learningAli Shafahi, Parsa Saadatpanah, Chen Zhu, Amin Ghiasi 等ICLR 2020 · 被引用 130 次
- With Great Training Comes Great Vulnerability: Practical Attacks against Transfer LearningBolun Wang, Yuanshun Yao, Bimal Viswanath, Haitao Zheng 等USENIX Security 2018 · 被引用 126 次
- Domain Adaptive Multi-Modality Neural Attention Network for Financial ForecastingDawei Zhou, Lecheng Zheng, Yada Zhu, Jianbo Li 等WWW 2020 · 被引用 51 次
- A Target-Agnostic Attack on Deep Models: Exploiting Security Vulnerabilities of Transfer LearningShahbaz Rezaei, Xin LiuICLR 2020 · 被引用 49 次
相关 Paper
- Understanding the Limits of Unsupervised Domain Adaptation via Data PoisoningAkshay Mehra, Bhavya Kailkhura, Pin-Yu Chen, Jihun HammNeurIPS 2021 · 被引用 30 次
- Protecting Model Adaptation from Trojans in the Unlabeled DataLijun Sheng, Jian Liang, Ran He, Zilei Wang 等AAAI 2025
- On the Adversarial Risk of Test Time Adaptation: An Investigation into Realistic Test-Time Data PoisoningYongyi Su, Yushu Li, Nanqing Liu, Kui Jia 等ICLR 2025
- Test-Time Poisoning Attacks Against Test-Time Adaptation ModelsTianshuo Cong, Xinlei He, Yun Shen, Yang ZhangS&P 2024 · 被引用 11 次
- Self-Domain Adaptation for Face Anti-SpoofingJingjing Wang, Jingyi Zhang, Ying Bian, Youyi Cai 等AAAI 2021 · 被引用 111 次
