AAAI 2026technical0 citations

Deferred Poisoning: Making the Model More Vulnerable via Hessian Singularization

Yuhao He, Jinyu Tian, Xianwei Zheng, Li Dong, Yuanman Li, Jiantao Zhou

Abstract

Recent studies have shown that deep learning models are very vulnerable to poisoning attacks. Many defense methods have been proposed to address this issue. However, traditional poisoning attacks are not as threatening as commonly believed. This is because they often cause differences in how the model performs on the training set compared to the validation set. Such inconsistency can alert defenders that their data has been poisoned, allowing them to take the necessary defensive actions. In this paper, we introduce a more threatening type of poisoning attack called the Deferred Poisoning Attack. This new attack allows the model to function normally during the training and validation phases but makes it very sensitive to evasion attacks or even natural noise. We achieve this by ensuring the poisoned model

BibTeX
@inproceedings{aaai2026_deferredpoisonin,
  title = {Deferred Poisoning: Making the Model More Vulnerable via Hessian Singularization},
  author = {Yuhao He and Jinyu Tian and Xianwei Zheng and Li Dong and Yuanman Li and Jiantao Zhou},
  booktitle = {AAAI 2026},
  year = {2026}
}
Deferred Poisoning: Making the Model More Vulnerable via Hessian Singularization · AAAI 2026