paper-with-me

홈 › Papers

Poison as a Cure: Detecting & Neutralizing Variable-Sized Backdoor Attacks in Deep Neural Networks

2019-11-19 · Alvin Chan, Yew-Soon Ong

Deep learning models have recently shown to be vulnerable to backdoor poisoning, an insidious attack where the victim model predicts clean images correctly but classifies the same images as the target class when a trigger poison pattern is added. This poison pattern can be embedded in the training dataset by the adversary. Existing defenses are effective under certain conditions such as a small size of the poison pattern, knowledge about the ratio of poisoned training samples or when a validated clean dataset is available. Since a defender may not have such prior knowledge or resources, we propose a defense against backdoor poisoning that is effective even when those prerequisites are not met. It is made up of several parts: one to extract a backdoor poison signal, detect poison target and base classes, and filter out poisoned from clean samples with proven guarantees. The final part of our defense involves retraining the poisoned model on a dataset augmented with the extracted poison signal and corrective relabeling of poisoned samples to neutralize the backdoor. Our approach has shown to be effective in defending against backdoor attacks that use both small and large-sized poison patterns on nine different target-base class pairs from the CIFAR10 dataset.

📄 PDF Abstract BibTeX arXiv:1911.08040

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

SecureAFL: Secure Asynchronous Federated Learning

2026-04-04 · Anjun Gao, Feng Wang, Zhenglin Wan, Yueyang Quan 외 arxiv

Federated learning (FL) enables multiple clients to collaboratively train a global machine learning model via a server without sharing their private training data. In traditional FL, the system follows a synchronous appr…

Federated Learning

Secure Retrieval-Augmented Generation against Poisoning Attacks

2025-10-28 · Zirui Cheng, Jikai Sun, Anjun Gao, Yueyang Quan 외 arxiv

Large language models (LLMs) have transformed natural language processing (NLP), enabling applications from content generation to decision support. Retrieval-Augmented Generation (RAG) improves LLMs by incorporating exte…

Preserving Privacy and Security in Federated Learning

2022-02-07 · Truc Nguyen, My T. Thai

Federated learning is known to be vulnerable to both security and privacy issues. Existing research has focused either on preventing poisoning attacks from users or on concealing the local model updates from the server, …

Federated Learning

SecureLearn -- An Attack-agnostic Defense for Multiclass Machine Learning Against Data Poisoning Attacks

2025-10-25 · Anum Paracha, Junaid Arshad, Mohamed Ben Farah, Khalid Ismail arxiv

Data poisoning attacks are a potential threat to machine learning (ML) models, aiming to manipulate training datasets to disrupt their performance. Existing defenses are mostly designed to mitigate specific poisoning att…

Adversarial Robustness

Spectral Signatures in Backdoor Attacks

2018-11-01 · NeurIPS 2018 12 · Brandon Tran, Jerry Li, Aleksander Madry

A recent line of work has uncovered a new form of data poisoning: so-called \emph{backdoor} attacks. These attacks are particularly dangerous because they do not affect a network's behavior on typical, benign data. Rathe…

Data Poisoning