ACQ: Few-shot Backdoor Defense via Activation Clipping and Quantizing

后门 计算机科学 深层神经网络 稳健性(进化) 人工智能 计算机安全 人工神经网络 生物化学 化学 基因
作者
Yulin Jin,Xiaoyu Zhang,Jian Lou,Xiaofeng Chen
标识
DOI:10.1145/3581783.3612410
摘要

In recent years, deep neural networks(DNNs) have relied on an increasing amount of training samples as the premise of the deployment for real-world scenarios. This gives rise to backdoor attacks, where a small fraction of poisoned data is inserted into the training dataset to manipulate the predictions of DNNs when presented with backdoor inputs. Backdoor attacks pose serious security threats during the prediction stage of DNNs. As a result, there is growing research attention to defend against backdoor attacks. This paper proposes Activation Clipping and Quantizing (ACQ), a novel backdoor elimination module via transforming the intermediate-layer output of DNNs during forward propagation by embedding Clipper and Quantizer into the backdoored DNNs. ACQ is motivated by the observation that the backdoored DNNs always output abnormally large or small intermediate-layer activations when presented with backdoored samples, eventually leading to the malicious prediction of backdoored DNNs. ACQ modifies backdoored DNNs to keep the intermediate-layer activations in a proper domain and align the forward propagation of backdoored samples with that of clean samples. Besides, we highlight that ACQ has the ability to eliminate the backdoor of DNNs in few-shot even zero-shot scenarios, which requires much fewer or even no clean samples for the backdoor elimination stage than existing approaches. Experiments demonstrate the effectiveness and robustness of ACQ against various attacks and tasks compared to existing methods. Our code and Appendix can be found in https://github.com/Backdoor-defense/ACQ
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
YY完成签到,获得积分10
1秒前
怡然百川完成签到 ,获得积分10
1秒前
8秒前
rocky15应助xiaosense采纳,获得10
9秒前
13秒前
16秒前
苏杰发布了新的文献求助10
18秒前
徐反宁完成签到,获得积分20
20秒前
小李同学完成签到,获得积分10
21秒前
23秒前
yzy应助闪闪草丛采纳,获得20
24秒前
桐桐应助AN采纳,获得10
24秒前
25秒前
苏杰完成签到,获得积分10
26秒前
27秒前
27秒前
希望天下0贩的0应助陶然采纳,获得10
28秒前
nn发布了新的文献求助10
29秒前
30秒前
30秒前
30秒前
左囧发布了新的文献求助10
31秒前
李健应助lyj采纳,获得30
32秒前
Aggielihui发布了新的文献求助10
33秒前
34秒前
Jasper应助科研通管家采纳,获得10
34秒前
wbero应助科研通管家采纳,获得20
34秒前
领导范儿应助科研通管家采纳,获得10
34秒前
英姑应助科研通管家采纳,获得10
34秒前
科研通AI2S应助科研通管家采纳,获得10
34秒前
34秒前
瓜尔佳发布了新的文献求助10
35秒前
等风来完成签到,获得积分10
36秒前
Hello应助歇歇采纳,获得10
37秒前
37秒前
38秒前
FashionBoy应助Nice采纳,获得30
39秒前
41秒前
41秒前
HuSP完成签到,获得积分10
42秒前
高分求助中
Sustainable Land Management: Strategies to Cope with the Marginalisation of Agriculture 1000
Corrosion and Oxygen Control 600
Python Programming for Linguistics and Digital Humanities: Applications for Text-Focused Fields 500
Love and Friendship in the Western Tradition: From Plato to Postmodernity 500
Heterocyclic Stilbene and Bibenzyl Derivatives in Liverworts: Distribution, Structures, Total Synthesis and Biological Activity 500
重庆市新能源汽车产业大数据招商指南(两链两图两池两库两平台两清单两报告) 400
Division and square root. Digit-recurrence algorithms and implementations 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 有机化学 工程类 生物化学 纳米技术 物理 内科学 计算机科学 化学工程 复合材料 遗传学 基因 物理化学 催化作用 电极 光电子学 量子力学
热门帖子
关注 科研通微信公众号,转发送积分 2549556
求助须知:如何正确求助?哪些是违规求助? 2176923
关于积分的说明 5607238
捐赠科研通 1897793
什么是DOI,文献DOI怎么找? 947353
版权声明 565447
科研通“疑难数据库(出版商)”最低求助积分说明 504094