Test-Time Poisoning Attacks Against Test-Time Adaptation Models

被引:0
|
作者
Cong, Tianshuo [1 ]
He, Xinlei [2 ]
Shen, Yun [3 ]
Zhang, Yang [2 ]
机构
[1] Tsinghua Univ, Beijing, Peoples R China
[2] CISPA Helmholtz Ctr Informat Secur, Saarbrucken, Germany
[3] NetApp, San Jose, CA USA
基金
国家重点研发计划;
关键词
D O I
10.1109/SP54263.2024.00072
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Deploying machine learning (ML) models in the wild is challenging as it suffers from distribution shifts, where the model trained on an original domain cannot generalize well to unforeseen diverse transfer domains. To address this challenge, several test-time adaptation (TTA) methods have been proposed to improve the generalization ability of the target pre-trained models under test data to cope with the shifted distribution. The success of TTA can be credited to the continuous fine-tuning of the target model according to the distributional hint from the test samples during test time. Despite being powerful, it also opens a new attack surface, i.e., test-time poisoning attacks, which are substantially different from previous poisoning attacks that occur during the training time of ML models (i.e., adversaries cannot intervene in the training process). In this paper, we perform the first test-time poisoning attack against four mainstream TTA methods, including TTT, DUA, TENT, and RPL. Concretely, we generate poisoned samples based on the surrogate models and feed them to the target TTA models. Experimental results show that the TTA methods are generally vulnerable to test-time poisoning attacks. For instance, the adversary can feed as few as 10 poisoned samples to degrade the performance of the target model from 76.20% to 41.83%. Our results demonstrate that TTA algorithms lacking a rigorous security assessment are unsuitable for deployment in real-life scenarios. As such, we advocate for the integration of defenses against test-time poisoning attacks into the design of TTA methods.(1)
引用
收藏
页码:1306 / 1324
页数:19
相关论文
共 50 条
  • [41] Online Adaptive Fault Diagnosis With Test-Time Domain Adaptation
    Wu, Kangkai
    Li, Jingjing
    Meng, Lichao
    Li, Fengling
    Lu, Ke
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2025, 21 (01) : 107 - 117
  • [42] Test-time Augmentation for Factual Probing
    Kamoda, Go
    Heinzerling, Benjamin
    Sakaguchi, Keisuke
    Inui, Kentaro
    FINDINGS OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS - EMNLP 2023, 2023, : 3650 - 3661
  • [43] Test-time adaptation for 6D pose tracking
    Tian, Long
    Oh, Changjae
    Cavallaro, Andrea
    PATTERN RECOGNITION, 2024, 152
  • [44] Noise-Robust Continual Test-Time Domain Adaptation
    Yu, Zhiqi
    Li, Jingjing
    Du, Zhekai
    Li, Fengling
    Zhu, Lei
    Yang, Yang
    PROCEEDINGS OF THE 31ST ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2023, 2023, : 2654 - 2662
  • [45] DARTH: Holistic Test-time Adaptation for Multiple Object Tracking
    Segu, Mattia
    Schiele, Bernt
    Yu, Fisher
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2023), 2023, : 9683 - 9693
  • [46] Test-Time Adaptation via Conjugate Pseudo-labels
    Goyal, Sachin
    Sun, Mingjie
    Raghunathan, Aditi
    Kolter, Zico
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35 (NEURIPS 2022), 2022,
  • [47] Test-time Adaptation for Machine Translation Evaluation by Uncertainty Minimization
    Zhan, Runzhe
    Liu, Xuebo
    Wong, Derek F.
    Zhang, Cuilian
    Chao, Lidia S.
    Zhang, Min
    PROCEEDINGS OF THE 61ST ANNUAL MEETING OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS, ACL 2023, VOL 1, 2023, : 807 - 820
  • [48] TEST-TIME ADAPTATION FOR OUT-OF-DISTRIBUTED IMAGE INPAINTING
    Shin, Chajin
    Kim, Taeoh
    Lee, Sangjin
    Lee, Sangyoun
    2021 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2021, : 2009 - 2013
  • [49] Test-Time Training on Video Streams
    Wang, Renhao
    Sun, Yu
    Tandon, Arnuv
    Gandelsman, Yossi
    Chen, Xinlei
    Efros, Alexei A.
    Wang, Xiaolong
    JOURNAL OF MACHINE LEARNING RESEARCH, 2025, 26 : 1 - 29
  • [50] Better Aggregation in Test-Time Augmentation
    Shanmugam, Divya
    Blalock, Davis
    Balakrishnan, Guha
    Guttag, John
    2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 1194 - 1203