DPC: Filtering Out Patch-Based Poisoned Samples with Differential Privacy

被引:0
|
作者
Yan, Yukun [1 ]
Tang, Peng [2 ]
Chen, Rui [1 ]
Han, Qilong [1 ]
Du, Ruochen [1 ]
机构
[1] Harbin Engn Univ, Harbin, Peoples R China
[2] Shandong Univ, Qingdao, Peoples R China
来源
COMPUTER SECURITY-ESORICS 2024, PT II | 2024年 / 14983卷
基金
中国国家自然科学基金;
关键词
Differential privacy; Data poisoning; Backdoor attacks;
D O I
10.1007/978-3-031-70890-9_15
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Patch-based data poisoning backdoor attacks have been exposed the vulnerability of deep neural networks (DNNs). While the differentially private training algorithm is a promising defense method, it faces significant challenges: 1) simultaneously limiting the fitting of clean and poisoned samples induces the degradation of clean accuracy, and 2) maintaining model stability struggles when poisoned samples dominate the target class. To address these challenges, we propose the Bioptimization Training Strategy, which integrates robust training with poisoned sample filtering techniques and conducts asynchronous optimization to complete the defense. Next, to implement this strategy, we combine the Differentially Private training algorithm with the Confusion training method to unveil a practical defense framework (DPC). This approach focuses on filtering out poisoned samples and retraining the model with the rest. To take full advantage of inherent stability of the differentially private training algorithm, even the poisoned samples dominate the target class, we adopt self-supervised pre-training to treat poisoned samples as outliers in the latent space. Then, the supervised fine-tuning algorithm enhanced with differential privacy can effectively limit the fitting of these poisoned samples. Additionally, we adaptively adjust the strength of differential privacy protection based on insights from filtered samples, improving clean sample fitting and further strengthening poison samples detection. Finally, our extensive experiments demonstrate that DPC (Our code is publicly available at https://github.com/yyk1997/DPC) preserves clean accuracy effectively while providing robust backdoor protection.
引用
收藏
页码:289 / 309
页数:21
相关论文
共 39 条
  • [31] De-noising Multi-coil Magnetic Resonance Imaging Using Patch-Based Adaptive Filtering in Wavelet Domain
    Omair Inam
    Mahmood Qureshi
    Hammad Omer
    Applied Magnetic Resonance, 2019, 50 : 1325 - 1343
  • [32] A Local-Clustering-Based Personalized Differential Privacy Framework for User-Based Collaborative Filtering
    Li, Yongkai
    Liu, Shubo
    Wang, Jun
    Liu, Mengjun
    DATABASE SYSTEMS FOR ADVANCED APPLICATIONS (DASFAA 2017), PT I, 2017, 10177 : 543 - 558
  • [33] A Simple, Compact Filtering Patch Antenna Based on Mode Analysis With Wide Out-of-Band Suppression
    Yang, Wanchen
    Zhang, Yingqi
    Che, Wenquan
    Xun, Mengzhu
    Xue, Quan
    Shen, Guangxu
    Feng, Wenjie
    IEEE TRANSACTIONS ON ANTENNAS AND PROPAGATION, 2019, 67 (10) : 6244 - 6253
  • [34] Random forest algorithm under differential privacy based on out-of-bag estimate
    Li Y.
    Chen J.
    Li Q.
    Liu A.
    Harbin Gongye Daxue Xuebao/Journal of Harbin Institute of Technology, 2021, 53 (02): : 146 - 154
  • [35] P1OVD: Patch-Based 1-Day Out-of-Bounds Vulnerabilities Detection Tool for Downstream Binaries
    Li, Hongyi
    He, Daojing
    Zhu, Xiaogang
    Chan, Sammy
    ELECTRONICS, 2022, 11 (02)
  • [36] A Differential Privacy Budget Allocation Algorithm Based on Out-of-Bag Estimation in Random Forest
    Li, Xin
    Qin, Baodong
    Luo, Yiyuan
    Zheng, Dong
    MATHEMATICS, 2022, 10 (22)
  • [37] Aerial camera image focusing method based on out-of-phase differential filtering effect
    Kang Q.
    Zheng L.
    Wang H.
    Hongwai yu Jiguang Gongcheng/Infrared and Laser Engineering, 2021, 50 (08):
  • [38] A Millimeter-Wave Differential Filtering Dual-Patch Antenna Based on Coupling Power Divider Feeding
    Yu, Zefang
    Wu, Yongle
    Wang, Weimin
    Zhuo, Murong
    Tian, Peng
    2020 IEEE ASIA-PACIFIC MICROWAVE CONFERENCE (APMC), 2020, : 552 - 554
  • [39] A Differential-Fed Dual-Polarized Microstrip Patch Filtering Antenna Based on Dual-Mode SIW Cavity
    Yu, Hao
    Qian, Suchuan
    Zhou, Xin
    Gu, Hongtao
    Zhang, Gang
    2024 IEEE INTERNATIONAL WORKSHOP ON RADIO FREQUENCY AND ANTENNA TECHNOLOGIES, IWRF&AT 2024, 2024, : 381 - 383