Influence Attributions can be Systematically Altered by Model Manipulation

Chhavi Yadav, Ruihan Wu, Kamalika Chaudhuri
Proceedings of The 29th International Conference on Artificial Intelligence and Statistics, PMLR 300:1396-1404, 2026.

Abstract

Influence Functions are a standard tool for attributing predictions to training data in a principled manner and are widely used in applications such as data valuation and fairness. In this work, we present realistic incentives to manipulate influence-based attributions and investigate whether these attributions can be \textit{systematically} altered by an adversary. We show that small systemic perturbations to models can indeed alter influence-based attributions \textit{as desired}. We work on logistic regression models trained on ResNet feature embeddings and standard tabular fairness datasets and provide efficient attacks with backward-friendly implementations. Our work raises questions on the reliability of influence-based attributions in adversarial circumstances.

Cite this Paper


BibTeX
@InProceedings{pmlr-v300-yadav26a, title = { Influence Attributions can be Systematically Altered by Model Manipulation }, author = {Yadav, Chhavi and Wu, Ruihan and Chaudhuri, Kamalika}, booktitle = {Proceedings of The 29th International Conference on Artificial Intelligence and Statistics}, pages = {1396--1404}, year = {2026}, editor = {Khan, Emtiyaz and Li, Yingzhen and Solin, Arno and Ramdas, Aaditya}, volume = {300}, series = {Proceedings of Machine Learning Research}, month = {02--05 May}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v300/main/assets/yadav26a/yadav26a.pdf}, url = {https://proceedings.mlr.press/v300/yadav26a.html}, abstract = { Influence Functions are a standard tool for attributing predictions to training data in a principled manner and are widely used in applications such as data valuation and fairness. In this work, we present realistic incentives to manipulate influence-based attributions and investigate whether these attributions can be \textit{systematically} altered by an adversary. We show that small systemic perturbations to models can indeed alter influence-based attributions \textit{as desired}. We work on logistic regression models trained on ResNet feature embeddings and standard tabular fairness datasets and provide efficient attacks with backward-friendly implementations. Our work raises questions on the reliability of influence-based attributions in adversarial circumstances. } }
Endnote
%0 Conference Paper %T Influence Attributions can be Systematically Altered by Model Manipulation %A Chhavi Yadav %A Ruihan Wu %A Kamalika Chaudhuri %B Proceedings of The 29th International Conference on Artificial Intelligence and Statistics %C Proceedings of Machine Learning Research %D 2026 %E Emtiyaz Khan %E Yingzhen Li %E Arno Solin %E Aaditya Ramdas %F pmlr-v300-yadav26a %I PMLR %P 1396--1404 %U https://proceedings.mlr.press/v300/yadav26a.html %V 300 %X Influence Functions are a standard tool for attributing predictions to training data in a principled manner and are widely used in applications such as data valuation and fairness. In this work, we present realistic incentives to manipulate influence-based attributions and investigate whether these attributions can be \textit{systematically} altered by an adversary. We show that small systemic perturbations to models can indeed alter influence-based attributions \textit{as desired}. We work on logistic regression models trained on ResNet feature embeddings and standard tabular fairness datasets and provide efficient attacks with backward-friendly implementations. Our work raises questions on the reliability of influence-based attributions in adversarial circumstances.
APA
Yadav, C., Wu, R. & Chaudhuri, K.. (2026). Influence Attributions can be Systematically Altered by Model Manipulation . Proceedings of The 29th International Conference on Artificial Intelligence and Statistics, in Proceedings of Machine Learning Research 300:1396-1404 Available from https://proceedings.mlr.press/v300/yadav26a.html.

Related Material