BadTouch: The First Study of Data Poisoning in Tactile Models
Abstract
Repeated tactile observations share a physical contact, but their supplied force labels need not share the same quality. How should a curator use this provenance when adapting a frozen tactile encoder? We study label-only poisoning on 904 public GelSight trajectories with same-input controls, two frozen encoder settings, and explicit verified-label budgets. A finite-bank deletion frontier separates errors made by a detector from correct samples necessarily lost through whole-contact removal. In the Sparsh curation bank, complete poison removal by whole-contact deletion requires deleting 93.69% of correct sharp candidate rows. Using the same trusted predictor and contact-calibrated thresholds, row deletion reduces this loss to 0.26% and sharp MAE from 0.092 to 0.054 N, at 99.67% poison recall for the 1.5 N target. This collateral improvement does not establish additional task value: when all 362 verified contacts can be reused, excluding unverified sharp candidates reaches ordinary/sharp MAE of 0.025/0.040 N, compared with 0.026/0.039 N after filtered augmentation. Lower-budget sharp gains vary across seeds. Source-allocation, calibration-scarcity, accepted-label and recovery controls delimit these findings within one acquisition population. The results show why provenance-aware curation must evaluate both deletion cost and predictive utility under the same available verified information.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.