pith:TA5KJQNT
Efficient Preference Poisoning Attack on Offline RLHF
Flipping one preference label in log-linear DPO creates a parameter-independent gradient shift that turns targeted poisoning into a binary sparse approximation problem.
arxiv:2605.02495 v2 · 2026-05-04 · cs.LG · cs.AI · stat.ML
Add to your LaTeX paper
\usepackage{pith}
\pithnumber{TA5KJQNT3FHIQUNJIMRGMI64ZB}
Prints a linked badge after your title and injects PDF metadata. Compiles on arXiv. Learn more · Embed verified badge
Record completeness
Claims
Flipping one preference label induces a parameter-independent shift in the DPO gradient, converting the targeted poisoning problem into a structured binary sparse approximation problem that BAL-A and BMP-A solve with sufficient conditions and coherence-based guarantees.
The central reduction assumes that the DPO objective is strictly log-linear in the parameters so that the gradient shift from a single label flip remains independent of the current parameter vector; if this independence fails for realistic non-linear models or regularizers, the conversion to sparse approximation no longer holds.
Label-flip attacks on log-linear DPO reduce to binary sparse approximation problems that can be solved efficiently by lattice-based and binary matching pursuit methods with recovery guarantees.
Formal links
Receipt and verification
| First computed | 2026-05-26T02:04:11.841288Z |
|---|---|
| Builder | pith-number-builder-2026-05-17-v1 |
| Signature | Pith Ed25519
(pith-v1-2026-05) · public key |
| Schema | pith-number/v1.0 |
Canonical hash
983aa4c1b3d94e8851a943226623dcc84bdf1b058985d897d42c7897ef4bb2de
Aliases
· · · · ·Agent API
Verify this Pith Number yourself
curl -sH 'Accept: application/ld+json' https://pith.science/pith/TA5KJQNT3FHIQUNJIMRGMI64ZB \
| jq -c '.canonical_record' \
| python3 -c "import sys,json,hashlib; b=json.dumps(json.loads(sys.stdin.read()), sort_keys=True, separators=(',',':'), ensure_ascii=False).encode(); print(hashlib.sha256(b).hexdigest())"
# expect: 983aa4c1b3d94e8851a943226623dcc84bdf1b058985d897d42c7897ef4bb2de
Canonical record JSON
{
"metadata": {
"abstract_canon_sha256": "168897d1319adf9cf5ca6ec100e90635defd2020f0090cbb82ced51119b27a71",
"cross_cats_sorted": [
"cs.AI",
"stat.ML"
],
"license": "http://creativecommons.org/licenses/by/4.0/",
"primary_cat": "cs.LG",
"submitted_at": "2026-05-04T11:45:38Z",
"title_canon_sha256": "6ce72836f72c2d4bc21da7421672596e800250bd45781c68f4170bcb702393f2"
},
"schema_version": "1.0",
"source": {
"id": "2605.02495",
"kind": "arxiv",
"version": 2
}
}