Test-Time Poisoning Attacks Against Test-Time Adaptation Models

被引:0
|
作者
Cong, Tianshuo [1 ]
He, Xinlei [2 ]
Shen, Yun [3 ]
Zhang, Yang [2 ]
机构
[1] Tsinghua Univ, Beijing, Peoples R China
[2] CISPA Helmholtz Ctr Informat Secur, Saarbrucken, Germany
[3] NetApp, San Jose, CA USA
基金
国家重点研发计划;
关键词
D O I
10.1109/SP54263.2024.00072
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Deploying machine learning (ML) models in the wild is challenging as it suffers from distribution shifts, where the model trained on an original domain cannot generalize well to unforeseen diverse transfer domains. To address this challenge, several test-time adaptation (TTA) methods have been proposed to improve the generalization ability of the target pre-trained models under test data to cope with the shifted distribution. The success of TTA can be credited to the continuous fine-tuning of the target model according to the distributional hint from the test samples during test time. Despite being powerful, it also opens a new attack surface, i.e., test-time poisoning attacks, which are substantially different from previous poisoning attacks that occur during the training time of ML models (i.e., adversaries cannot intervene in the training process). In this paper, we perform the first test-time poisoning attack against four mainstream TTA methods, including TTT, DUA, TENT, and RPL. Concretely, we generate poisoned samples based on the surrogate models and feed them to the target TTA models. Experimental results show that the TTA methods are generally vulnerable to test-time poisoning attacks. For instance, the adversary can feed as few as 10 poisoned samples to degrade the performance of the target model from 76.20% to 41.83%. Our results demonstrate that TTA algorithms lacking a rigorous security assessment are unsuitable for deployment in real-life scenarios. As such, we advocate for the integration of defenses against test-time poisoning attacks into the design of TTA methods.(1)
引用
收藏
页码:1306 / 1324
页数:19
相关论文
共 50 条
  • [21] Improved Self-Training for Test-Time Adaptation
    Ma, Jing
    2024 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2024, : 23701 - 23710
  • [22] Prototypical class-wise test-time adaptation
    Lee, Hojoon
    Lee, Seunghwan
    Jung, Inyoung
    Korea, Sungeun Hong
    PATTERN RECOGNITION LETTERS, 2025, 187 : 49 - 55
  • [23] Efficient Test-Time Model Adaptation without Forgetting
    Niu, Shuaicheng
    Wu, Jiaxiang
    Zhang, Yifan
    Chen, Yaofo
    Zheng, Shijian
    Zhao, Peilin
    Tan, Mingkui
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 162, 2022,
  • [24] Unraveling Batch Normalization for Realistic Test-Time Adaptation
    Su, Zixian
    Guo, Jingwei
    Yao, Kai
    Yang, Xi
    Wang, Qiufeng
    Huang, Kaizhu
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 13, 2024, : 15136 - 15144
  • [25] Test-time Domain Adaptation for Monocular Depth Estimation
    Li, Zhi
    Sh, Shaoshuai
    Schiele, Bernt
    Dai, Dengxin
    2023 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND AUTOMATION, ICRA, 2023, : 4873 - 4879
  • [26] Test-Time Collective Prediction
    Mendler-Duenner, Celestine
    Guo, Wenshuo
    Bates, Stephen
    Jordan, Michael I.
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021,
  • [27] VPA: Fully Test-Time Visual Prompt Adaptation
    Sun, Jiachen
    Ibrahim, Mark
    Hall, Melissa
    Evtimov, Ivan
    Mao, Z. Morley
    Ferrer, Cristian Canton
    Hazirbas, Caner
    PROCEEDINGS OF THE 31ST ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2023, 2023, : 5796 - 5806
  • [28] Exploring Motion Cues for Video Test-Time Adaptation
    Zeng, Runhao
    Deng, Qi
    Xu, Huixuan
    Niu, Shuaicheng
    Chen, Jian
    PROCEEDINGS OF THE 31ST ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2023, 2023, : 1840 - 1850
  • [29] Test-Time Adaptation with Shape Moments for Image Segmentation
    Bateson, Mathilde
    Lombaert, Herve
    Ben Ayed, Ismail
    MEDICAL IMAGE COMPUTING AND COMPUTER ASSISTED INTERVENTION, MICCAI 2022, PT IV, 2022, 13434 : 736 - 745
  • [30] Multi-source fully test-time adaptation
    Du, Yuntao
    Luo, Siqi
    Xin, Yi
    Chen, Mingcai
    Feng, Shuai
    Zhang, Mujie
    Wang, Chonngjun
    NEURAL NETWORKS, 2025, 181