Uncovering Adversarial Risks of Test-Time Adaptation
Tong Wu, Feiran Jia, Xiangyu Qi, Jiachen T. Wang, Vikash Sehwag, Saeed Mahloujifar, Prateek Mittal
摘要
Recently, test-time adaptation (TTA) has been proposed as a promising solution for addressing distribution shifts. It allows a base model to adapt to an unforeseen distribution during inference by leveraging the information from the batch of (unlabeled) test data. However, we uncover a novel security vulnerability of TTA based on the insight that predictions on benign samples can be impacted by malicious samples in the same batch. To exploit this vulnerability, we propose Distribution Invading Attack (DIA), which injects a small fraction of malicious data into the test batch. DIA causes models using TTA to misclassify benign and unperturbed test data, providing an entirely new capability for adversaries that is infeasible in canonical machine learning pipelines. Through comprehensive evaluations, we demonstrate the high effectiveness of our attack on multiple benchmarks across six TTA methods. In response, we investigate two countermeasures to robustify the existing insecure TTA implementations, following the principle of "security by design". Together, we hope our findings can make the community aware of the utility-security tradeoffs in deploying TTA and provide valuable insights for developing robust TTA approaches.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- SoTTA: Robust Test-Time Adaptation on Noisy Data StreamsTaesik Gong, Yewon Kim, Taeckyung Lee, Sorn Chottananurak 等NeurIPS 2023 · 被引用 89 次
- Optimization-Free Test-Time Adaptation for Cross-Person Activity RecognitionShuoyuan Wang, Jindong Wang, Huajun Xi, Bob Zhang 等UbiComp 2024 · 被引用 16 次
- Monitoring Risks in Test-Time AdaptationMona Schirmer, Metod Jazbec, Christian Andersson Naesseth, Eric T. NalisnickNeurIPS 2025 · 被引用 10 次
- MedBN: Robust Test-Time Adaptation against Malicious Test SamplesHyejin Park, Jeongyeon Hwang, Sunung Mun, Sangdon Park 等CVPR 2024 · 被引用 1 次
- On the Adversarial Vulnerability of Label-Free Test-Time AdaptationShahriar Rifat, Jonathan D. Ashdown, Michael J. De Lucia, Ananthram Swami 等ICLR 2025
它引用的顶会 Paper43
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- The Many Faces of Robustness: A Critical Analysis of Out-of-Distribution GeneralizationDan Hendrycks, Steven Basart, Norman Mu, Saurav Kadavath 等ICCV 2021 · 被引用 2,294 次
- Tent: Fully Test-Time Adaptation by Entropy MinimizationDequan Wang, Evan Shelhamer, Shaoteng Liu, Bruno A. Olshausen 等ICLR 2021 · 被引用 1,731 次
- Do We Really Need to Access the Source Data? Source Hypothesis Transfer for Unsupervised Domain AdaptationJian Liang, Dapeng Hu, Jiashi FengICML 2020 · 被引用 1,624 次
- AugMix: A Simple Data Processing Method to Improve Robustness and UncertaintyDan Hendrycks, Norman Mu, Ekin Dogus Cubuk, Barret Zoph 等ICLR 2020 · 被引用 1,572 次
相关 Paper
- Test-Time Poisoning Attacks Against Test-Time Adaptation ModelsTianshuo Cong, Xinlei He, Yun Shen, Yang ZhangS&P 2024 · 被引用 11 次
- On the Adversarial Risk of Test Time Adaptation: An Investigation into Realistic Test-Time Data PoisoningYongyi Su, Yushu Li, Nanqing Liu, Kui Jia 等ICLR 2025
- On Pitfalls of Test-Time AdaptationHao Zhao, Yuejiang Liu, Alexandre Alahi, Tao LinICML 2023 · 被引用 72 次
- PTTA: Purifying Malicious Samples for Test-Time Model AdaptationJing Ma, Hanlin Li, Xiang XiangICML 2025
- Label Shift Adapter for Test-Time Adaptation under Covariate and Label ShiftsSunghyun Park, Seunghan Yang, Jaegul Choo, Sungrack YunICCV 2023 · 被引用 28 次
