paper-with-me

홈 › Papers

Backdoor Defense via Decoupling the Training Process

2022-02-05 · ICLR 2022 4 · Kunzhe Huang, Yiming Li, Baoyuan Wu, Zhan Qin, Kui Ren

Recent studies have revealed that deep neural networks (DNNs) are vulnerable to backdoor attacks, where attackers embed hidden backdoors in the DNN model by poisoning a few training samples. The attacked model behaves normally on benign samples, whereas its prediction will be maliciously changed when the backdoor is activated. We reveal that poisoned samples tend to cluster together in the feature space of the attacked DNN model, which is mostly due to the end-to-end supervised training paradigm. Inspired by this observation, we propose a novel backdoor defense via decoupling the original end-to-end training process into three stages. Specifically, we first learn the backbone of a DNN model via \emph{self-supervised learning} based on training samples without their labels. The learned backbone will map samples with the same ground-truth label to similar locations in the feature space. Then, we freeze the parameters of the learned backbone and train the remaining fully connected layers via standard training with all (labeled) training samples. Lastly, to further alleviate side-effects of poisoned samples in the second stage, we remove labels of some `low-credible' samples determined based on the learned model and conduct a \emph{semi-supervised fine-tuning} of the whole model. Extensive experiments on multiple benchmark datasets and DNN models verify that the proposed defense is effective in reducing backdoor threats while preserving high accuracy in predicting benign samples. Our code is available at \url{https://github.com/SCLBD/DBD}.

📄 PDF Abstract BibTeX arXiv:2202.03423

Code (3)

sclbd/dbd 공식 구현 pytorch
sclbd/backdoorbench pytorch
yjandali/BackdoorBench-MergeGuard pytorch

Tasks

backdoor defenseSelf-Supervised Learning

Similar Papers 제목 키워드 기반

You Can Backdoor Personalized Federated Learning

2023-07-29 · Tiandi Ye, Cen Chen, Yinggui Wang, Xiang Li 외

Existing research primarily focuses on backdoor attacks and defenses within the generic federated learning scenario, where all clients collaborate to train a single global model. A recent study conducted by Qin et al. (2…

Backdoor AttackFederated LearningMeta-LearningPersonalized Federated Learning

Mitigating Backdoors via Decoy Shortcuts and Knowledge Decoupling

2026-08-01 · Zixuan Zhu, Rui Wang, Lihua Jing, Jinwen Zhong arxiv

Backdoor attacks pose a serious threat to deep neural networks, especially when training relies on third-party data, allowing adversaries to inject malicious behaviors through data poisoning. In this work, we reveal that…

Towards A Proactive ML Approach for Detecting Backdoor Poison Samples

2022-05-26 · Xiangyu Qi, Tinghao Xie, Jiachen T. Wang, Tong Wu 외

Adversaries can embed backdoors in deep learning models by introducing backdoor poison samples into training datasets. In this work, we investigate how to detect such poison samples to mitigate the threat of backdoor att…

Expose Before You Defend: Unifying and Enhancing Backdoor Defenses via Exposed Models

2024-10-25 · Yige Li, Hanxun Huang, Jiaming Zhang, Xingjun Ma 외

Backdoor attacks covertly implant triggers into deep neural networks (DNNs) by poisoning a small portion of the training data with pre-designed backdoor triggers. This vulnerability is exacerbated in the era of large mod…

backdoor defenseModel EditingSST-2

REFINE: Inversion-Free Backdoor Defense via Model Reprogramming

2025-02-22 · Yukun Chen, Shuo Shao, Enhao Huang, Yiming Li 외

Backdoor attacks on deep neural networks (DNNs) have emerged as a significant security threat, allowing adversaries to implant hidden malicious behaviors during the model training phase. Pre-processing-based defense, whi…

backdoor defense