A new paper introduces a theoretical framework to analyze data poisoning attacks and defenses in continual learning (CL). The research frames the adversary-defender interaction as an online zero-sum game, establishing that no defense can succeed if an adversary poisons a linear proportion of tasks with unbounded noise or pattern shifts in regularization-based CL. The paper also proposes defenses for scenarios with infrequent attacks or bounded noise, including a task-to-task verification mechanism and a robust defense that minimizes sensitivity to poisoned features. AI
IMPACT Provides a theoretical foundation for understanding and mitigating data poisoning risks in continual learning systems.
RANK_REASON The cluster contains an academic paper detailing a new theoretical framework for analyzing attacks and defenses in continual learning. [lever_c_demoted from research: ic=1 ai=1.0]
Read on Hugging Face Daily Papers →
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →