On the Fragility of Data Attribution When Learning Is Distributed
Xian Gao, Bo Hui, MIN-TE SUN, Wei-Shinn Ku
摘要
Data attribution has become an important component of pricing, auditing, and governance in machine learning pipelines, yet most attribution methods implicitly assume that attribution values faithfully reflect participants' contributions. We show that this assumption can fail: a single participant in a standard distributed training workflow can substantially inflate its measured attribution value while preserving global utility. Our attribution-first attack uses latent optimization to inject small synthetic batches that preserve utility while exploiting non-IID label coverage and evaluator sensitivities. Across datasets, models, and multiple marginal-utility evaluators, the attack consistently increases the adversary’s attribution value and reshapes the relative attribution structure among benign clients without degrading accuracy or triggering geometry-based defenses. These results show that attribution itself forms a new attack surface and motivate the development of attribution-robust and incentive-compatible scoring mechanisms.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper41
- Addressing Class Imbalance in Federated LearningLixu Wang, Shichao Xu, Xiao Wang, Qi ZhuAAAI 2021 · 被引用 314 次
- Intriguing Properties of Data Attribution on Diffusion ModelsXiaosen Zheng, Tianyu Pang, Chao Du, Jing Jiang 等ICLR 2024 · 被引用 41 次
- Training Data Attribution via Approximate UnrollingJuhan Bae, Wu Lin, Jonathan Lorraine, Roger B. GrosseNeurIPS 2024 · 被引用 41 次
- Incentives in Federated Learning: Equilibria, Dynamics, and Mechanisms for Welfare MaximizationAniket Murhekar, Zhuowen Yuan, Bhaskar Ray Chaudhury, Bo Li 等NeurIPS 2023 · 被引用 37 次
- Fair and Efficient Contribution Valuation for Vertical Federated LearningZhenan Fan, Huang Fang, Xinglu Wang, Zirui Zhou 等ICLR 2024 · 被引用 33 次
相关 Paper
- Adversarial Attacks on Data AttributionXinhe Wang, Pingbang Hu, Junwei Deng, Jiaqi W. MaICLR 2025
- Faithful Group Shapley ValueKiljae Lee, Ziqi Liu, Weijing Tang, Yuan ZhangNeurIPS 2025 · 被引用 4 次
- ACE: A Model Poisoning Attack on Contribution Evaluation Methods in Federated LearningZhangchen Xu, Fengqing Jiang, Luyao Niu, Jinyuan Jia 等USENIX Security 2024 · 被引用 11 次
- Rescaled Influence Functions: Accurate Data Attribution in High DimensionIttai Rubinstein, Samuel B. HopkinsNeurIPS 2025 · 被引用 3 次
- Local Model Poisoning Attacks to Byzantine-Robust Federated LearningMinghong Fang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongUSENIX Security 2020
