Data-Poisoning Audits for Causal Effect Estimation
Summary
A new data-poisoning audit framework, published on 2026-07-22, addresses the vulnerability of observational causal analyses that pool records from multiple sources. It introduces a greedy scan to compute exact finite-sample worst-case movement at various append budgets, assuming fixed preprocessing. For scenarios with nuisance refitting, the framework derives a total-influence score, combining direct record contributions with effects through propensity and outcome models. It also provides a conservative finite-budget bound for fully refitted estimates. Simulations confirm the exact results and show total influence improves local refit prediction, while analyses on multisite and public data reveal material sensitivity even with small append budgets. This framework translates adversarial data-composition risk into movement curves and critical budgets.
Key takeaway
For Data Scientists or AI Security Engineers conducting observational causal analyses, you must assess data integrity against append-only attacks. This framework provides tools to quantify adversarial data-composition risk, allowing you to identify critical budgets and design robust source-level safeguards. Implement these audits to ensure more reliable causal reporting and protect against malicious data manipulation.
Key insights
Observational causal analyses pooling data are vulnerable to append-only attacks, requiring auditing.
Principles
- Pooled observational data risks append-only attacks.
- Adversaries can strategically alter reported treatment effects.
Method
A greedy scan computes exact worst-case movement; a total-influence score accounts for nuisance refitting via propensity and outcome models.
In practice
- Translate data-composition risk into movement curves.
- Identify critical append budgets.
- Design source-level safeguards.
Topics
- Data Poisoning
- Causal Inference
- Observational Studies
- Append-Only Attacks
- Inverse-Probability-Weighted Estimation
- Data Integrity
Best for: Research Scientist, CTO, VP of Engineering/Data, AI Scientist, Data Scientist, AI Security Engineer
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by Machine Learning.