{"url":"/task/data-poisoning","name":"Data Poisoning","slug":"data-poisoning","description_markdown":"**Data Poisoning** is an adversarial attack that tries to manipulate the training dataset in order to control the prediction behavior of a trained model such that the model will label malicious examples into a desired classes (e.g., labeling spam e-mails as safe).\r\n\r\n\r\n<span class=\"description-source\">Source: [Explaining Vulnerabilities to Adversarial Machine Learning through Visual Analytics ](https://arxiv.org/abs/1907.07296)</span>","categories":[{"name":"Adversarial","url":"/area/adversarial"}],"source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","slug_source":"derived"},"counts":{"papers_tagged":492,"papers_with_code":170,"benchmarks":0,"benchmark_tables_in_archive":0,"benchmark_tables_shown":0,"benchmark_tables_withheld_as_spam":0,"benchmark_definition":"a leaderboard table with at least one row; benchmark_tables_shown also counts the zero-row tables; benchmark_tables_in_archive adds the tables withheld as spam","datasets":0,"subtasks":0,"parent_tasks":0},"benchmarks":[],"datasets":[],"subtasks":[],"parent_tasks":[],"papers":{"order":"repositories listed in the archive (desc), then date (desc); the archive holds no stars","population":"papers tagged with this task that list at least one repository in the archive","shown":30,"of":170,"tagged_in_all":492,"items":[{"url":"/paper/poison-frogs-targeted-clean-label-poisoning","title":"Poison Frogs! Targeted Clean-Label Poisoning Attacks on Neural Networks","date":"2018-04-03","arxiv_id":"1804.00792","repositories_listed":5,"syntology":null},{"url":"/paper/imma-immunizing-text-to-image-models-against","title":"IMMA: Immunizing text-to-image Models against Malicious Adaptation","date":"2023-11-30","arxiv_id":"2311.18815","repositories_listed":3,"syntology":{"n":17,"n_ran":1,"n_unverified":16,"n_pointer_only":0}},{"url":"/paper/analysis-and-detectability-of-offline-data","title":"Analysis and Detectability of Offline Data Poisoning Attacks on Linear Dynamical Systems","date":"2022-11-16","arxiv_id":"2211.08804","repositories_listed":3,"syntology":null},{"url":"/paper/adversarial-examples-make-strong-poisons","title":"Adversarial Examples Make Strong Poisons","date":"2021-06-21","arxiv_id":"2106.10807","repositories_listed":3,"syntology":{"n":2,"n_ran":2,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/how-to-backdoor-federated-learning","title":"How To Backdoor Federated Learning","date":"2018-07-02","arxiv_id":"1807.00459","repositories_listed":3,"syntology":{"n":1,"n_ran":1,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/2d-oob-attributing-data-contribution-through","title":"2D-OOB: Attributing Data Contribution Through Joint Valuation Framework","date":"2024-08-07","arxiv_id":"2408.03572","repositories_listed":2,"syntology":null},{"url":"/paper/2408-02946","title":"Data Poisoning in LLMs: Jailbreak-Tuning and Scaling Laws","date":"2024-08-06","arxiv_id":"2408.02946","repositories_listed":2,"syntology":{"n":5,"n_ran":1,"n_unverified":4,"n_pointer_only":5}},{"url":"/paper/mitigating-backdoor-attack-by-injecting","title":"Mitigating Backdoor Attack by Injecting Proactive Defensive Backdoor","date":"2024-05-25","arxiv_id":"2405.16112","repositories_listed":2,"syntology":{"n":5,"n_ran":4,"n_unverified":1,"n_pointer_only":5}},{"url":"/paper/defending-against-patch-based-backdoor","title":"Defending Against Patch-based Backdoor Attacks on Self-Supervised Learning","date":"2023-04-04","arxiv_id":"2304.01482","repositories_listed":2,"syntology":null},{"url":"/paper/run-off-election-improved-provable-defense","title":"Run-Off Election: Improved Provable Defense against Data Poisoning Attacks","date":"2023-02-05","arxiv_id":"2302.02300","repositories_listed":2,"syntology":{"n":1,"n_ran":1,"n_unverified":0,"n_pointer_only":1}},{"url":"/paper/corruptencoder-data-poisoning-based-backdoor","title":"CorruptEncoder: Data Poisoning based Backdoor Attacks to Contrastive Learning","date":"2022-11-15","arxiv_id":"2211.08229","repositories_listed":2,"syntology":null},{"url":"/paper/not-all-poisons-are-created-equal-robust","title":"Not All Poisons are Created Equal: Robust Training against Data Poisoning","date":"2022-10-18","arxiv_id":"2210.09671","repositories_listed":2,"syntology":{"n":12,"n_ran":4,"n_unverified":8,"n_pointer_only":0}},{"url":"/paper/adversarial-robustness-of-representation","title":"Adversarial Robustness of Representation Learning for Knowledge Graphs","date":"2022-09-30","arxiv_id":"2210.00122","repositories_listed":2,"syntology":null},{"url":"/paper/autoregressive-perturbations-for-data","title":"Autoregressive Perturbations for Data Poisoning","date":"2022-06-08","arxiv_id":"2206.03693","repositories_listed":2,"syntology":{"n":5,"n_ran":3,"n_unverified":2,"n_pointer_only":2}},{"url":"/paper/bilevel-optimization-with-a-lower-level","title":"Bilevel Optimization with a Lower-level Contraction: Optimal Sample Complexity without Warm-start","date":"2022-02-07","arxiv_id":"2202.03397","repositories_listed":2,"syntology":{"n":8,"n_ran":8,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/data-poisoning-attacks-on-regression-learning","title":"Data Poisoning Attacks on Regression Learning and Corresponding Defenses","date":"2020-09-15","arxiv_id":"2009.07008","repositories_listed":2,"syntology":null},{"url":"/paper/witches-brew-industrial-scale-data-poisoning","title":"Witches' Brew: Industrial Scale Data Poisoning via Gradient Matching","date":"2020-09-04","arxiv_id":"2009.02276","repositories_listed":2,"syntology":{"n":5,"n_ran":4,"n_unverified":1,"n_pointer_only":5}},{"url":"/paper/data-poisoning-attacks-against-federated","title":"Data Poisoning Attacks Against Federated Learning Systems","date":"2020-07-16","arxiv_id":"2007.08432","repositories_listed":2,"syntology":{"n":3,"n_ran":0,"n_unverified":3,"n_pointer_only":0}},{"url":"/paper/just-how-toxic-is-data-poisoning-a-unified","title":"Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning Attacks","date":"2020-06-22","arxiv_id":"2006.12557","repositories_listed":2,"syntology":{"n":10,"n_ran":0,"n_unverified":10,"n_pointer_only":0}},{"url":"/paper/metapoison-practical-general-purpose-clean","title":"MetaPoison: Practical General-purpose Clean-label Data Poisoning","date":"2020-04-01","arxiv_id":"2004.00225","repositories_listed":2,"syntology":{"n":3,"n_ran":2,"n_unverified":1,"n_pointer_only":3}},{"url":"/paper/radioactive-data-tracing-through-training","title":"Radioactive data: tracing through training","date":"2020-02-03","arxiv_id":"2002.00937","repositories_listed":2,"syntology":null},{"url":"/paper/penalty-method-for-inversion-free-deep","title":"Penalty Method for Inversion-Free Deep Bilevel Optimization","date":"2019-11-08","arxiv_id":"1911.03432","repositories_listed":2,"syntology":null},{"url":"/paper/trojdrl-trojan-attacks-on-deep-reinforcement","title":"TrojDRL: Trojan Attacks on Deep Reinforcement Learning Agents","date":"2019-03-01","arxiv_id":"1903.06638","repositories_listed":2,"syntology":null},{"url":"/paper/stronger-data-poisoning-attacks-break-data","title":"Stronger Data Poisoning Attacks Break Data Sanitization Defenses","date":"2018-11-02","arxiv_id":"1811.00741","repositories_listed":2,"syntology":null},{"url":"/paper/certified-defenses-for-data-poisoning-attacks","title":"Certified Defenses for Data Poisoning Attacks","date":"2017-06-09","arxiv_id":"1706.03691","repositories_listed":2,"syntology":null},{"url":"/paper/addressing-the-devastating-effects-of-single","title":"Addressing The Devastating Effects Of Single-Task Data Poisoning In Exemplar-Free Continual Learning","date":"2025-07-05","arxiv_id":"2507.04106","repositories_listed":1,"syntology":null},{"url":"/paper/vlms-can-aggregate-scattered-training-patches","title":"VLMs Can Aggregate Scattered Training Patches","date":"2025-06-04","arxiv_id":"2506.03614","repositories_listed":1,"syntology":null},{"url":"/paper/does-low-rank-adaptation-lead-to-lower","title":"Does Low Rank Adaptation Lead to Lower Robustness against Training-Time Attacks?","date":"2025-05-19","arxiv_id":"2505.12871","repositories_listed":1,"syntology":{"n":1,"n_ran":0,"n_unverified":1,"n_pointer_only":1}},{"url":"/paper/adversarial-robustness-of-deep-learning-1","title":"Adversarial Robustness of Deep Learning Models for Inland Water Body Segmentation from SAR Images","date":"2025-05-03","arxiv_id":"2505.01884","repositories_listed":1,"syntology":null},{"url":"/paper/data-poisoning-in-deep-learning-a-survey","title":"Data Poisoning in Deep Learning: A Survey","date":"2025-03-27","arxiv_id":"2503.22759","repositories_listed":1,"syntology":null}],"syntology_records":14,"syntology_note":"a paper without a record is not a recorded non-run: it may lack an arXiv id or simply be absent from the graph layer"},"description_links":{"kept":0,"unwrapped_to_text":0,"bare_urls_linked":0,"relative_images_dropped":0,"rule":"internal links are kept only when the target slug exists in the catalog"},"syntology":{"read_at":"2026-09-24T18:15:14+00:00","claim":"Per-sample execution status on synthesized fixtures ('ran N of M samples'); not a correctness claim and not a ranking signal.","status_vocabulary":{"ran_honours":"ran, honoured the contract we drafted","ran_violates":"ran, violated the contract we drafted","ran_draft_wrong":"ran; our contract draft was wrong, not the code","ran_fixture":"ran; our fixture could not drive it","ran":"ran on a synthesized input","unverified":"unverified (harvested, no recorded run)"}},"not_shown":{"libraries":"the archive has no per-task library table","trend_sparklines":"the Trend column of the benchmarks table was a rendered image; it is not in the archive","social_and_latest_sorts":"stars and social signals are not in the archive"}}