用户群体通过集体查询扰动,无需平台配合即可纠正算法偏见。
Test-Time Collective Action: Proxy-Based Perturbations for Correcting Algorithmic Harms

- 用户共用查询接口,构建平台代理并优化通用扰动以修正偏差。
- 小规模集体可缩小子群准确率差距,提升最差组表现和公平性指标。
- 适合无权干预平台训练的弱势群体,尤其适用于延迟修复场景。
当机器学习系统对特定子群表现不佳时,受影响用户通常无法自行纠正。现有公平性方法依赖平台方修复,而近期算法集体行动研究显示,协调用户可引导系统达成目标,但需平台重新训练用户修改后的数据,用户难以掌控。本文提出测试时集体行动(TTCA)框架,使共享查询访问权限的用户群体可在不参与平台训练的前提下,修正服务不足子群的偏差。该框架通过代理机制,集体利用黑箱API提取平台代理,针对每个类别优化通用扰动;每位成员在提交输入时应用该扰动,无需平台协作。在CIFAR-10、CIFAR-100和FairFace上的实验表明,适度规模的集体可显著缩小子群准确率差距,具备跨模型迁移能力(小代理可攻击大平台),并提升最差组准确率、等机会差距与差异影响。查询预算分析显示,集体池化比单个用户独立攻击更高效。测试时集体行动为平台修复延迟或不可行时提供了有效的用户端纠偏手段。
原文摘要 · Abstract (English)
When machine learning systems under-perform for particular subgroups, affected users typically have no way to correct these disparities without relying on platform-level fixes. Existing approaches to algorithmic fairness rely on provider-centric approaches to correct these failures, leaving users with no external lever when faced with harm. Recent work in Algorithmic Collective Action shows that coordinated users can steer an algorithmic system toward a collective goal, but the existing mechanisms require the provider to retrain on the collective's modified data which users may not have control over. We propose Test-Time Collective Action (TTCA), a framework through which a group of users who share query access to the platform, can correct disparities affecting under-served subgroup without participating in the platform's training loop. We implement this through a proxy-based mechanism where the collective pools query access to a black-box API to extract a proxy of the platform, then optimizes a per-class universal perturbation against the proxy. Each member applies this perturbation to their own inputs at submission time, requiring no cooperation from the platform. We empirically evaluate the mechanism on CIFAR-10, CIFAR-100, and FairFace, showing that modestly-sized collectives close most of the subgroup accuracy gap, transfer across architectures (a small proxy can attack a larger platform), and improve worst-group accuracy, equal-opportunity gap, and disparate impact. A query-budget analysis comparing a per-user black-box attack baseline shows that pooling is cheaper than each subgroup member attacking alone. Test-time collective action thus offers corrective intervention to users when platform-side remediation is unavailable or delayed.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。