On the Fragility of Data Attribution When Learning Is Distributed

Xian Gao, Bo Hui, Min-Te Sun, Wei-Shinn Ku
Proceedings of the 43rd International Conference on Machine Learning, PMLR 306:33214-33234, 2026.

Abstract

Data attribution has become an important component of pricing, auditing, and governance in machine learning pipelines, yet most attribution methods implicitly assume that attribution values faithfully reflect participants’ contributions. We show that this assumption can fail: a single participant in a standard distributed training workflow can substantially inflate its measured attribution value while preserving global utility. Our attribution-first attack uses latent optimization to inject small synthetic batches that preserve utility while exploiting non-IID label coverage and evaluator sensitivities. Across datasets, models, and multiple marginal-utility evaluators, the attack consistently increases the adversary’s attribution value and reshapes the relative attribution structure among benign clients without degrading accuracy or triggering geometry-based defenses. These results show that attribution itself forms a new attack surface and motivate the development of attribution-robust and incentive-compatible scoring mechanisms.

Cite this Paper


BibTeX
@InProceedings{pmlr-v306-gao26k, title = {On the Fragility of Data Attribution When Learning Is Distributed}, author = {Gao, Xian and Hui, Bo and Sun, Min-Te and Ku, Wei-Shinn}, booktitle = {Proceedings of the 43rd International Conference on Machine Learning}, pages = {33214--33234}, year = {2026}, editor = {Zhang, Tong and Dudik, Miroslav and Jaggi, Martin and Agarwal, Alekh and Li, Sharon and Schuurmans, Dale and Zhu, Jerry and Berkenkamp, Felix and Dong, Hanze and Bietti, Alberto}, volume = {306}, series = {Proceedings of Machine Learning Research}, month = {06--11 Jul}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v306/main/assets/gao26k/gao26k.pdf}, url = {https://proceedings.mlr.press/v306/gao26k.html}, abstract = {Data attribution has become an important component of pricing, auditing, and governance in machine learning pipelines, yet most attribution methods implicitly assume that attribution values faithfully reflect participants’ contributions. We show that this assumption can fail: a single participant in a standard distributed training workflow can substantially inflate its measured attribution value while preserving global utility. Our attribution-first attack uses latent optimization to inject small synthetic batches that preserve utility while exploiting non-IID label coverage and evaluator sensitivities. Across datasets, models, and multiple marginal-utility evaluators, the attack consistently increases the adversary’s attribution value and reshapes the relative attribution structure among benign clients without degrading accuracy or triggering geometry-based defenses. These results show that attribution itself forms a new attack surface and motivate the development of attribution-robust and incentive-compatible scoring mechanisms.} }
Endnote
%0 Conference Paper %T On the Fragility of Data Attribution When Learning Is Distributed %A Xian Gao %A Bo Hui %A Min-Te Sun %A Wei-Shinn Ku %B Proceedings of the 43rd International Conference on Machine Learning %C Proceedings of Machine Learning Research %D 2026 %E Tong Zhang %E Miroslav Dudik %E Martin Jaggi %E Alekh Agarwal %E Sharon Li %E Dale Schuurmans %E Jerry Zhu %E Felix Berkenkamp %E Hanze Dong %E Alberto Bietti %F pmlr-v306-gao26k %I PMLR %P 33214--33234 %U https://proceedings.mlr.press/v306/gao26k.html %V 306 %X Data attribution has become an important component of pricing, auditing, and governance in machine learning pipelines, yet most attribution methods implicitly assume that attribution values faithfully reflect participants’ contributions. We show that this assumption can fail: a single participant in a standard distributed training workflow can substantially inflate its measured attribution value while preserving global utility. Our attribution-first attack uses latent optimization to inject small synthetic batches that preserve utility while exploiting non-IID label coverage and evaluator sensitivities. Across datasets, models, and multiple marginal-utility evaluators, the attack consistently increases the adversary’s attribution value and reshapes the relative attribution structure among benign clients without degrading accuracy or triggering geometry-based defenses. These results show that attribution itself forms a new attack surface and motivate the development of attribution-robust and incentive-compatible scoring mechanisms.
APA
Gao, X., Hui, B., Sun, M. & Ku, W.. (2026). On the Fragility of Data Attribution When Learning Is Distributed. Proceedings of the 43rd International Conference on Machine Learning, in Proceedings of Machine Learning Research 306:33214-33234 Available from https://proceedings.mlr.press/v306/gao26k.html.

Related Material