acceptodds
Under review as a conference paper at ICLR 2027

Robust Conformal Anomaly Detection under Calibration Poisoning

Abstract

Conformal prediction is routinely used to wrap an anomaly detector in a distribution-free coverage guarantee. That guarantee is about normal samples only, and we show it can be satisfied by a detector that has stopped working. When an attacker places a small fraction of high-scoring points into the calibration set, the conformal threshold moves past the range of plausible normal scores, so coverage on normal data is met or exceeded while recall on true anomalies falls to near zero. We give a closed-form account: the operating level of standard split conformal under upper-tail contamination is , so at exactly the detector stops raising false alarms and keeps only whatever power comes from anomalies scoring beyond the clean support, a collapse point predictable before any experiment is run. We then analyze a trimmed-quantile calibration rule with the level correction . Writing its threshold as an order statistic of the full calibration sample reduces the analysis to two short concentration arguments and yields a two-sided bracket on the operating level whose upward drift is rather than , a power bound, and an expression for attainable coverage that shows where a symmetric trim can be driven and motivates a one-sided variant needing no contamination parameter. Across 5 tabular benchmarks, 5 detectors, 3 attacker models, and frozen CLIP and MiniLM embeddings, standard conformal retains 12 to 19 percent of its clean power at and 4 to 7 percent at , and percent on an autoencoder, while the trimmed rule stays above 97 percent everywhere.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.