Test-Time Poisoning Attacks Against Test-Time Adaptation Models

被引:0
|
作者
Cong, Tianshuo [1 ]
He, Xinlei [2 ]
Shen, Yun [3 ]
Zhang, Yang [2 ]
机构
[1] Tsinghua Univ, Beijing, Peoples R China
[2] CISPA Helmholtz Ctr Informat Secur, Saarbrucken, Germany
[3] NetApp, San Jose, CA USA
基金
国家重点研发计划;
关键词
D O I
10.1109/SP54263.2024.00072
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Deploying machine learning (ML) models in the wild is challenging as it suffers from distribution shifts, where the model trained on an original domain cannot generalize well to unforeseen diverse transfer domains. To address this challenge, several test-time adaptation (TTA) methods have been proposed to improve the generalization ability of the target pre-trained models under test data to cope with the shifted distribution. The success of TTA can be credited to the continuous fine-tuning of the target model according to the distributional hint from the test samples during test time. Despite being powerful, it also opens a new attack surface, i.e., test-time poisoning attacks, which are substantially different from previous poisoning attacks that occur during the training time of ML models (i.e., adversaries cannot intervene in the training process). In this paper, we perform the first test-time poisoning attack against four mainstream TTA methods, including TTT, DUA, TENT, and RPL. Concretely, we generate poisoned samples based on the surrogate models and feed them to the target TTA models. Experimental results show that the TTA methods are generally vulnerable to test-time poisoning attacks. For instance, the adversary can feed as few as 10 poisoned samples to degrade the performance of the target model from 76.20% to 41.83%. Our results demonstrate that TTA algorithms lacking a rigorous security assessment are unsuitable for deployment in real-life scenarios. As such, we advocate for the integration of defenses against test-time poisoning attacks into the design of TTA methods.(1)
引用
收藏
页码:1306 / 1324
页数:19
相关论文
共 50 条
  • [31] Category-Aware Test-Time Training Domain Adaptation
    Feng, Yangqin
    Xu, Xinxing
    Fu, Huazhu
    Wang, Yan
    Wang, Zizhou
    Zhen, Liangli
    Goh, Rick Siow Mong
    Liu, Yong
    2024 IEEE CONFERENCE ON ARTIFICIAL INTELLIGENCE, CAI 2024, 2024, : 300 - 306
  • [32] MT3: Meta Test-Time Training for Self-Supervised Test-Time Adaption
    Bartler, Alexander
    Buehler, Andre
    Wiewel, Felix
    Doebler, Mario
    Yang, Bin
    INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND STATISTICS, VOL 151, 2022, 151
  • [33] Multiple Teacher Model for Continual Test-Time Domain Adaptation
    Wang, Ran
    Zuo, Hua
    Fang, Zhen
    Lu, Jie
    ADVANCES IN ARTIFICIAL INTELLIGENCE, AI 2023, PT I, 2024, 14471 : 304 - 314
  • [34] Compression and restoration: exploring elasticity in continual test-time adaptation
    Li, Jingwei
    Liu, Chengbao
    Bai, Xiwei
    Tan, Jie
    Chu, Jiaqi
    Wang, Yudong
    MACHINE LEARNING, 2025, 114 (04)
  • [35] A Comprehensive Survey on Test-Time Adaptation Under Distribution Shifts
    Liang, Jian
    He, Ran
    Tan, Tieniu
    INTERNATIONAL JOURNAL OF COMPUTER VISION, 2025, 133 (01) : 31 - 64
  • [36] Robust Mean Teacher for Continual and Gradual Test-Time Adaptation
    Doebler, Mario
    Marsden, Robert A.
    Yang, Bin
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR, 2023, : 7704 - 7714
  • [37] On-the-Fly Test-time Adaptation for Medical Image Segmentation
    Valanarasu, Jeya Maria Jose
    Guo, Pengfei
    Vibashan, V. S.
    Patel, Vishal M.
    MEDICAL IMAGING WITH DEEP LEARNING, VOL 227, 2023, 227 : 586 - 598
  • [38] Exploring Safety Supervision for Continual Test-time Domain Adaptation
    Yang, Xu
    Gu, Yanan
    Wei, Kun
    Deng, Cheng
    PROCEEDINGS OF THE THIRTY-SECOND INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, IJCAI 2023, 2023, : 1649 - 1657
  • [39] SoTTA: Robust Test-Time Adaptation on Noisy Data Streams
    Gong, Taesik
    Kim, Yewon
    Lee, Taeckyung
    Chottananurak, Sorn
    Lee, Sung-Ju
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [40] Self-supervised Test-time Adaptation on Video Data
    Azimi, Fatemeh
    Palacio, Sebastian
    Raue, Federico
    Hees, Joern
    Bertinetto, Luca
    Dengel, Andreas
    2022 IEEE WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV 2022), 2022, : 2603 - 2612