
Federated Test-Time Adaptation (FTTA) studies how decentralized models can adapt to client-specific distribution shifts at test time using unlabeled local data, without sharing raw data. This project examines a largely unexplored security risk in that setting: adversarial clients manipulating their local test streams to corrupt the collaborative adaptation. Under a realistic grey-box threat model, we develop FedPoisonTTP, an attack framework that uses a surrogate aggregator, posterior distillation, and feature-distribution regularization to construct stealthy, in-distribution poisoned samples that transfer across clients. We also adapt existing test-time poisoning strategies to common FTTA mechanisms such as batch-normalization adaptation and entropy minimization. Experiments on CIFAR-10-C and CIFAR-100-C reveal substantial and persistent performance degradation, motivating stronger defenses for federated test-time personalization. A paper on this work was published in CVPR Workshop 2026 (FedVision).
Team: Md Akil Raihan Iftee, Syed Md. Ahnaf Hasan, Amin Ahsan Ali, AKM Mahbubur Rahman, Sajib Mistry, Aneesh Krishna


