Understanding the Limits of Unsupervised Domain Adaptation via Data Poisoning
Akshay Mehra, Bhavya Kailkhura, Pin-Yu Chen, Jihun Hamm
摘要
Unsupervised domain adaptation (UDA) enables cross-domain learning without target domain labels by transferring knowledge from a labeled source domain whose distribution differs from that of the target. However, UDA is not always successful and several accounts of `negative transfer' have been reported in the literature. In this work, we prove a simple lower bound on the target domain error that complements the existing upper bound. Our bound shows the insufficiency of minimizing source domain error and marginal distribution mismatch for a guaranteed reduction in the target domain error, due to the possible increase of induced labeling function mismatch. This insufficiency is further illustrated through simple distributions for which the same UDA approach succeeds, fails, and may succeed or fail with an equal chance. Motivated from this, we propose novel data poisoning attacks to fool UDA methods into learning representations that produce large target domain errors. We evaluate the effect of these attacks on popular UDA methods using benchmark datasets where they have been previously shown to be successful. Our results show that poisoning can significantly decrease the target domain accuracy, dropping it to almost 0% in some cases, with the addition of only 10% poisoned data in the source domain. The failure of these UDA methods demonstrates their limitations at guaranteeing cross-domain generalization consistent with our lower bound. Thus, evaluating UDA methods in adversarial settings such as data poisoning provides a better sense of their robustness to data distributions unfavorable for UDA.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Better Safe Than Sorry: Preventing Delusive Adversaries with Adversarial TrainingLue Tao, Lei Feng, Jinfeng Yi, Sheng-Jun Huang 等NeurIPS 2021 · 被引用 90 次
- Understanding the Transferability of Representations via Task-RelatednessAkshay Mehra, Yunbei Zhang, Jihun HammNeurIPS 2024 · 被引用 13 次
- Uncovering Adversarial Risks of Test-Time AdaptationTong Wu, Feiran Jia, Xiangyu Qi, Jiachen T. Wang 等ICML 2023 · 被引用 12 次
- Domain Adaptation with Adaptive -Divergence: Tighter Variational Representation and Generalization BoundsZhe Cheng, Fode Zhang, Yifan Zhu, Lingrui Wang 等ICML 2026
它引用的顶会 Paper4
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu 等S&P 2018 · 被引用 867 次
- MetaPoison: Practical General-purpose Clean-label Data PoisoningW. Ronny Huang, Jonas Geiping, Liam Fowl, Gavin Taylor 等NeurIPS 2020 · 被引用 242 次
- Domain Adaptation with Conditional Distribution Matching and Generalized Label ShiftRemi Tachet des Combes, Han Zhao, Yu-Xiang Wang, Geoffrey J. GordonNeurIPS 2020 · 被引用 231 次
- How Robust Are Randomized Smoothing Based Defenses to Data Poisoning?Akshay Mehra, Bhavya Kailkhura, Pin-Yu Chen, Jihun HammCVPR 2021
相关 Paper
- Indirect Invisible Poisoning Attacks on Domain AdaptationJun Wu, Jingrui HeKDD 2021 · 被引用 15 次
- Distributionally Robust Classification for Multi-source Unsupervised Domain AdaptationSeonghwi Kim, Sungho Jo, Wooseok Ha, Minwoo ChaeICLR 2026 · 被引用 4 次
- CASUAL: Conditional Support Alignment for Domain Adaptation with Label ShiftAnh T. Nguyen, Lam Tran, Anh Tong, Tuan-Duy H. Nguyen 等AAAI 2025 · 被引用 3 次
- Information-Theoretic Analysis of Unsupervised Domain AdaptationZiqiao Wang, Yongyi MaoICLR 2023 · 被引用 4 次
- Unknown-Aware Domain Adversarial Learning for Open-Set Domain AdaptationJoonHo Jang, Byeonghu Na, DongHyeok Shin, Mingi Ji 等NeurIPS 2022 · 被引用 85 次
