paper-with-me

홈 › Papers

Merge Now, Regret Later: The Hidden Cost of Model Merging Is Adversarial Transferability

2025-09-28 · Ankit Gangwal, Aaryan Ajay Sharma arxiv

Model Merging (MM) has proven to be an effective alternative to multi-task learning, where several fine-tuned models are merged, without access to the tasks' training data, into one model that retains performance across different tasks. Recent works have explored the security of MM, showing how MM can confer robustness against various adversarial attacks. However, none of them has sufficiently explored its impact on transfer attacks using transferable adversarial examples. In this work, we study the effect of MM on the transferability of adversarial examples. We perform comprehensive evaluations and statistical analysis consisting of eight MM methods, seven datasets, and six attack methods, sweeping over 336 distinct attack settings. Through it, we first challenge the prevailing notion of MM conferring free adversarial robustness, and show that MM cannot reliably defend against transfer attacks, with over 80% transfer rate. Moreover, we reveal two key insights for machine-learning practitioners regarding MM and transferability for a robust system design: (1) stronger MM methods increase vulnerability to transfer attacks and (2) mitigating representation bias increases vulnerability to transfer attacks. We also find weight averaging as an exception to (1), i.e., it is found to be the most vulnerable method to transfer attacks, despite being the weakest MM method. Finally, we analyze the underlying reasons for these findings, show how an adversary with limited information could launch an attack, and provide potential solutions. These findings offer actionable insights for deploying MM in security-sensitive machine-learning systems.

📄 PDF Abstract BibTeX arXiv:2509.23689

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial RobustnessMulti-Task LearningAdversarial Attack

Similar Papers 제목 키워드 기반

Merger Analysis with Latent Price

2024-04-11 · Paul S. Koh

Standard empirical tools for merger analysis assume price data, which are often unavailable. I characterize sufficient conditions for identifying the unilateral effects of mergers without price data using the first-order…

FeatCal: Feature Calibration for Post-Merging Models

2026-05-13 · Yanggan Gu, Shuo Cai, Zihao Wang, Wenjun Wang 외 arxiv

Model merging combines task experts into one model and avoids joint training, retraining, or deploying many expert models, but the merged model often still underperforms task experts. We study this performance gap throug…

Provable Scaling Laws of Feature Emergence from Learning Dynamics of Grokking

2025-09-25 · Yuandong Tian arxiv

While the phenomenon of grokking, i.e., delayed generalization, has been studied extensively, it remains an open problem whether there is a mathematical framework that characterizes what kind of features will emerge, how…

Distributed Online Convex Optimization with Time-Varying Coupled Inequality Constraints

2019-03-06 · Xinlei Yi, Xiuxian Li, Lihua Xie, Karl H. Johansson

This paper considers distributed online optimization with time-varying coupled inequality constraints. The global objective function is composed of local convex cost and regularization functions and the coupled constrain…

Non-Cooperative Games with Uncertainty

2025-02-27 · Jozsef Konczer

This paper introduces a framework for finite non-cooperative games where each player faces a globally uncertain parameter with no common prior. Every player chooses both a mixed strategy and projects an emergent subjecti…

Decision Making