Data Poisoning Attacks against Conformal Prediction
Yangyi Li, Aobo Chen, Wei Qian, Chenxu Zhao, Divya Lidder, Mengdi Huai
摘要
The efficient and theoretically sound uncertainty quantification is crucial for building trust in deep learning models. This has spurred a growing interest in conformal prediction (CP), a powerful technique that provides a model-agnostic and distribution-free method for obtaining conformal prediction sets with theoretical guarantees. However, the vulnerabilities of such CP methods with regard to dedicated data poisoning attacks have not been studied previously. To bridge this gap, for the first time, we in this paper propose a new class of black-box data poisoning attacks against CP, where the adversary aims to cause the desired manipulations of some specific examples' prediction uncertainty results (instead of misclassifications). Additionally, we design novel optimization frameworks for our proposed attacks. Further, we conduct extensive experiments to validate the effectiveness of our attacks on various settings (e.g., the full and split CP settings). Notably, our extensive experiments show that our attacks are more effective in manipulating uncertainty results than traditional poisoning attacks that aim at inducing misclassifications, and existing defenses against conventional attacks are ineffective against our proposed attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Membership Inference Attacks With False Discovery Rate ControlChenxu Zhao, Wei Qian, Aobo Chen, Mengdi HuaiICCV 2025 · 被引用 2 次
- Provably Reliable Conformal Prediction Sets in the Presence of Data PoisoningYan Scholten, Stephan GünnemannICLR 2025
- Efficient Robust Conformal Prediction via Lipschitz-Bounded NetworksThomas Massena, Léo Andéol, Thibaut Boissin, Franck Mamalet 等ICML 2025
- Enhancing Adversarial Robustness with Conformal Prediction: A Framework for Guaranteed Model ReliabilityJie Bao, Chuangyin Dang, Rui Luo, Hanwei Zhang 等ICML 2025
它引用的顶会 Paper35
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Sharpness-aware Minimization for Efficiently Improving GeneralizationPierre Foret, Ariel Kleiner, Hossein Mobahi, Behnam NeyshaburICLR 2021 · 被引用 1,861 次
- Classification with Valid and Adaptive CoverageYaniv Romano, Matteo Sesia, Emmanuel J. CandèsNeurIPS 2020 · 被引用 586 次
- Anti-Backdoor Learning: Training Clean Models on Poisoned DataYige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu 等NeurIPS 2021 · 被引用 503 次
- Witches' Brew: Industrial Scale Data Poisoning via Gradient MatchingJonas Geiping, Liam H. Fowl, W. Ronny Huang, Wojciech Czaja 等ICLR 2021 · 被引用 268 次
相关 Paper
- Ensemble Conformal Predictor (EnCP): A New Conformal Predictor with Robustness Guarantees Against Data Poisoning AttacksYuxin Yang, Qiang Li, Runyang Feng, Liren Shan 等S&P 2026
- Robust Yet Efficient Conformal Prediction SetsSoroush H. Zargarbashi, Mohammad Sadegh Akhondzadeh, Aleksandar BojchevskiICML 2024 · 被引用 19 次
- Verifiably Robust Conformal PredictionLinus Jeary, Tom Kuipers, Mehran Hosseini, Nicola PaolettiNeurIPS 2024 · 被引用 16 次
- Direct Prediction Set Minimization via Bilevel Conformal Classifier TrainingYuanjie Shi, Hooman Shahrokhi, Xuesong Jia, Xiongzhi Chen 等ICML 2025
- Adversarially Robust Conformal PredictionAsaf Gendler, Tsui-Wei Weng, Luca Daniel, Yaniv RomanoICLR 2022 · 被引用 51 次
