Continual-learning-specific detection of future-targeting poisoned samples
Develop detection methods for adversarial perturbations that identify poisoned samples targeting future iterations in continual-learning systems, rather than only detecting perturbations affecting the current iteration.
References
Adapting such detectors to the continual-learning setting, where poisoned samples target not the current but a future iteration, is an open problem that our threat model makes explicit.
— Catastrophic Learning: A New Attack Vector on Continual Learning Networks
(2608.18976 - Kluss et al., 19 Aug 2026) in Section 5, “Stealthiness of the PGD-based Attacks”