DPC: Filtering Out Patch-Based Poisoned Samples with Differential Privacy

被引:0
|
作者
Yan, Yukun [1 ]
Tang, Peng [2 ]
Chen, Rui [1 ]
Han, Qilong [1 ]
Du, Ruochen [1 ]
机构
[1] Harbin Engn Univ, Harbin, Peoples R China
[2] Shandong Univ, Qingdao, Peoples R China
来源
COMPUTER SECURITY-ESORICS 2024, PT II | 2024年 / 14983卷
基金
中国国家自然科学基金;
关键词
Differential privacy; Data poisoning; Backdoor attacks;
D O I
10.1007/978-3-031-70890-9_15
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Patch-based data poisoning backdoor attacks have been exposed the vulnerability of deep neural networks (DNNs). While the differentially private training algorithm is a promising defense method, it faces significant challenges: 1) simultaneously limiting the fitting of clean and poisoned samples induces the degradation of clean accuracy, and 2) maintaining model stability struggles when poisoned samples dominate the target class. To address these challenges, we propose the Bioptimization Training Strategy, which integrates robust training with poisoned sample filtering techniques and conducts asynchronous optimization to complete the defense. Next, to implement this strategy, we combine the Differentially Private training algorithm with the Confusion training method to unveil a practical defense framework (DPC). This approach focuses on filtering out poisoned samples and retraining the model with the rest. To take full advantage of inherent stability of the differentially private training algorithm, even the poisoned samples dominate the target class, we adopt self-supervised pre-training to treat poisoned samples as outliers in the latent space. Then, the supervised fine-tuning algorithm enhanced with differential privacy can effectively limit the fitting of these poisoned samples. Additionally, we adaptively adjust the strength of differential privacy protection based on insights from filtered samples, improving clean sample fitting and further strengthening poison samples detection. Finally, our extensive experiments demonstrate that DPC (Our code is publicly available at https://github.com/yyk1997/DPC) preserves clean accuracy effectively while providing robust backdoor protection.
引用
收藏
页码:289 / 309
页数:21
相关论文
共 39 条
  • [21] Improved Collaborative Filtering Recommendation Algorithm Based on Differential Privacy Protection
    Yin, Chunyong
    Shi, Lingfeng
    Wang, Jin
    ADVANCED MULTIMEDIA AND UBIQUITOUS ENGINEERING, MUE/FUTURETECH 2018, 2019, 518 : 253 - 258
  • [22] Patch-Based U-Net Model for Isotropic Quantitative Differential Phase Contrast Imaging
    Li, An-Cin
    Vyas, Sunil
    Lin, Yu-Hsiang
    Huang, Yi-You
    Huang, Hsuan-Ming
    Luo, Yuan
    IEEE TRANSACTIONS ON MEDICAL IMAGING, 2021, 40 (11) : 3229 - 3237
  • [23] A Differential Private Collaborative Filtering Framework Based on Privacy-Relevance of Topics
    Feng, Tingting
    Guo, Yuchun
    Chen, Yishuai
    2016 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATION (ISCC), 2016, : 946 - 951
  • [24] New Collaborative Filtering Algorithms Based on SVD plus plus and Differential Privacy
    Xian, Zhengzheng
    Li, Qiliang
    Li, Gai
    Li, Lei
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2017, 2017
  • [25] Distinguishing Structures from Textures by Patch-based Contrasts around Pixels for High-quality and Efficient Texture filtering
    Wang, Shengchun
    Xu, Panpan
    Hou, Fei
    Wang, Wencheng
    Zhao, Chong
    COMPUTER GRAPHICS FORUM, 2024, 43 (07)
  • [26] DynaEgo: Privacy-Preserving Collaborative Filtering Recommender System Based on Social-Aware Differential Privacy
    Yan, Shen
    Pan, Shiran
    Zhu, Wen-Tao
    Chen, Keke
    INFORMATION AND COMMUNICATIONS SECURITY, ICICS 2016, 2016, 9977 : 347 - 357
  • [27] De-noising Multi-coil Magnetic Resonance Imaging Using Patch-Based Adaptive Filtering in Wavelet Domain
    Inam, Omair
    Qureshi, Mahmood
    Omer, Hammad
    APPLIED MAGNETIC RESONANCE, 2019, 50 (11) : 1325 - 1343
  • [28] Patch-Based Low-Rank Matrix Completion for Learning of Shape and Motion Models from Few Training Samples
    Ehrhardt, Jan
    Wilms, Matthias
    Handels, Heinz
    COMPUTER VISION - ECCV 2016, PT IV, 2016, 9908 : 712 - 727
  • [29] An adaptive edge-preserving image denoising technique using patch-based weighted-SVD filtering in wavelet domain
    Jain, Paras
    Tyagi, Vipin
    MULTIMEDIA TOOLS AND APPLICATIONS, 2017, 76 (02) : 1659 - 1679
  • [30] An adaptive edge-preserving image denoising technique using patch-based weighted-SVD filtering in wavelet domain
    Paras Jain
    Vipin Tyagi
    Multimedia Tools and Applications, 2017, 76 : 1659 - 1679