Unsupervised domain adaptation (UDA) enables cross-domain learning without\ntarget domain labels by transferring knowledge from a labeled source domain\nwhose distribution differs from that of the target. However, UDA is not always\nsuccessful and several accounts of `negative transfer' have been reported in\nthe literature. In this work, we prove a simple lower bound on the target\ndomain error that complements the existing upper bound. Our bound shows the\ninsufficiency of minimizing source domain error and marginal distribution\nmismatch for a guaranteed reduction in the target domain error, due to the\npossible increase of induced labeling function mismatch. This insufficiency is\nfurther illustrated through simple distributions for which the same UDA\napproach succeeds, fails, and may succeed or fail with an equal chance.\nMotivated from this, we propose novel data poisoning attacks to fool UDA\nmethods into learning representations that produce large target domain errors.\nWe evaluate the effect of these attacks on popular UDA methods using benchmark\ndatasets where they have been previously shown to be successful. Our results\nshow that poisoning can significantly decrease the target domain accuracy,\ndropping it to almost 0% in some cases, with the addition of only 10% poisoned\ndata in the source domain. The failure of these UDA methods demonstrates their\nlimitations at guaranteeing cross-domain generalization consistent with our\nlower bound. Thus, evaluating UDA methods in adversarial settings such as data\npoisoning provides a better sense of their robustness to data distributions\nunfavorable for UDA.\n