DPC: Filtering Out Patch-Based Poisoned Samples with Differential Privacy

被引:0
|
作者
Yan, Yukun [1 ]
Tang, Peng [2 ]
Chen, Rui [1 ]
Han, Qilong [1 ]
Du, Ruochen [1 ]
机构
[1] Harbin Engn Univ, Harbin, Peoples R China
[2] Shandong Univ, Qingdao, Peoples R China
来源
COMPUTER SECURITY-ESORICS 2024, PT II | 2024年 / 14983卷
基金
中国国家自然科学基金;
关键词
Differential privacy; Data poisoning; Backdoor attacks;
D O I
10.1007/978-3-031-70890-9_15
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Patch-based data poisoning backdoor attacks have been exposed the vulnerability of deep neural networks (DNNs). While the differentially private training algorithm is a promising defense method, it faces significant challenges: 1) simultaneously limiting the fitting of clean and poisoned samples induces the degradation of clean accuracy, and 2) maintaining model stability struggles when poisoned samples dominate the target class. To address these challenges, we propose the Bioptimization Training Strategy, which integrates robust training with poisoned sample filtering techniques and conducts asynchronous optimization to complete the defense. Next, to implement this strategy, we combine the Differentially Private training algorithm with the Confusion training method to unveil a practical defense framework (DPC). This approach focuses on filtering out poisoned samples and retraining the model with the rest. To take full advantage of inherent stability of the differentially private training algorithm, even the poisoned samples dominate the target class, we adopt self-supervised pre-training to treat poisoned samples as outliers in the latent space. Then, the supervised fine-tuning algorithm enhanced with differential privacy can effectively limit the fitting of these poisoned samples. Additionally, we adaptively adjust the strength of differential privacy protection based on insights from filtered samples, improving clean sample fitting and further strengthening poison samples detection. Finally, our extensive experiments demonstrate that DPC (Our code is publicly available at https://github.com/yyk1997/DPC) preserves clean accuracy effectively while providing robust backdoor protection.
引用
收藏
页码:289 / 309
页数:21
相关论文
共 39 条
  • [1] Patch-based image correlation with rapid filtering
    Guo, Guodong
    Dyer, Charles R.
    2007 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, VOLS 1-8, 2007, : 2883 - +
  • [2] Comparison of Patch-Based Approaches for Interferometric Phase Filtering
    Lin, Xue
    Niu, Dongmei
    Fang, Dongsheng
    2019 INTERNATIONAL SYMPOSIUM ON SIGNAL PROCESSING SYSTEMS (SPSS 2019), 2019, : 10 - 14
  • [3] Patch-based Privacy Preserving Neural Network for Vision Tasks
    Mabuchi, Mitsuhiro
    Ishikawa, Tetsuya
    2023 IEEE/CVF WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV), 2023, : 1550 - 1559
  • [4] PATCH-BASED TEXTURE SYNTHESIS USING DIFFERENTIAL EVOLUTION
    Tiwari, Arti
    Kumar, Sushil
    Gupta, Subhash Chand
    Pant, Millie
    2017 8TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2017,
  • [5] Modified patch-based locally optimal wiener for interferometric phase filtering
    Wang, Yang
    Huang, Haifeng
    Dong, Zhen
    Wu, Manqing
    Guofang Keji Daxue Xuebao/Journal of National University of Defense Technology, 2015, 37 (04): : 99 - 105
  • [6] Patch-based Privacy Attention for Weakly-supervised Privacy-Preserving Action Recognition
    Li, Xiao
    Qiu, Yu-Kun
    Peng, Yi-Xing
    Zheng, Wei-Shi
    2024 IEEE 18TH INTERNATIONAL CONFERENCE ON AUTOMATIC FACE AND GESTURE RECOGNITION, FG 2024, 2024,
  • [7] AllFocus: Patch-Based Video Out-of-Focus Blur Reconstruction
    Wang, Yinting
    Wang, Zhenyang
    Tao, Dapeng
    Zhuo, Shaojie
    Xu, Xianghua
    Pu, Shiliang
    Song, Mingli
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2017, 27 (09) : 1895 - 1908
  • [8] A Patch-Based Saliency Detection Method for Assessing the Visual Privacy Levels of Objects in Photos
    Li, Xuan
    Li, Dehua
    Yang, Zhi
    Chen, Weiwei
    IEEE ACCESS, 2017, 5 : 24332 - 24343
  • [9] Investigation of EEG Noise and Artifact Removal by Patch-Based and Kernel Adaptive Filtering Techniques
    Ghanem, Noha H.
    Eltrass, Ahmed S.
    Ismail, Nour H.
    2018 IEEE INTERNATIONAL SYMPOSIUM ON MEDICAL MEASUREMENTS AND APPLICATIONS (MEMEA), 2018, : 85 - 89
  • [10] Modified patch-based locally optimal Wiener method for interferometric SAR phase filtering
    Wang, Yang
    Huang, Haifeng
    Dong, Zhen
    Wu, Manqing
    ISPRS JOURNAL OF PHOTOGRAMMETRY AND REMOTE SENSING, 2016, 114 : 10 - 23