Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

On the Fragility of Data Attribution When Learning Is Distributed

About

Data attribution has become an important component of pricing, auditing, and governance in machine learning pipelines, yet most attribution methods implicitly assume that attribution values faithfully reflect participants' contributions. We show that this assumption can fail: a single participant in a standard distributed training workflow can substantially inflate its measured attribution value while preserving global utility. Our attribution-first attack uses latent optimization to inject small synthetic batches that preserve utility while exploiting non-IID label coverage and evaluator sensitivities. Across datasets, models, and multiple marginal-utility evaluators, the attack consistently increases the adversary's attribution value and reshapes the relative attribution structure among benign clients without degrading accuracy or triggering geometry-based defenses. These results show that attribution itself forms a new attack surface and motivate the development of attribution-robust and incentive-compatible scoring mechanisms.

Xian Gao, Bo Hui, Min-Te Sun, Wei-Shinn Ku• 2026

Related benchmarks

TaskDatasetResultRank
Data AttributionCIFAR-10
Data Attribution Value0.1682
15
Data AttributionSVHN
Normalized Data Attribution Value0.1256
15
Data AttributionFashionMNIST
Data Attribution Value0.1072
15
Attribution ManipulationCIFAR-10
Attribution Value0.1547
9
Showing 4 of 4 rows

Other info

Follow for update