VarDefense: Variance-Based Defense against Poison Attack

被引:0
作者
Fan, Mingyuan [1 ]
Du, Xue [1 ]
Liu, Ximeng [1 ]
Guo, Wenzhong [1 ]
机构
[1] Fuzhou Univ, Coll Comp & Data Sci, Fuzhou 350108, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
10.1155/2021/1974822
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The emergence of poison attack brings a serious risk to deep neural networks (DNNs). Specifically, an adversary can poison the training dataset to train a backdoor model, which behaves fine on clean data but induces targeted misclassification on arbitrary data with the crafted trigger. However, previous defense methods have to purify the backdoor model with the compromising degradation of performance. In this paper, to relieve the problem, a novel defense method VarDefense is proposed, which leverages an effective metric, i.e., variance, and purifying strategy. In detail, variance is adopted to distinguish the bad neurons that play a core role in poison attack and then purifying the bad neurons. Moreover, we find that the bad neurons are generally located in the later layers of the backdoor model because the earlier layers only extract general features. Based on it, we design a proper purifying strategy where only later layers of the backdoor model are purified and in this way, the degradation of performance is greatly reduced, compared to previous defense methods. Extensive experiments show that the performance of VarDefense significantly surpasses state-of-the-art defense methods.
引用
收藏
页数:9
相关论文
共 50 条
  • [21] Variance-based uncertainty relation for incompatible observers
    Xiao Zheng
    Guo-Feng Zhang
    Quantum Information Processing, 2017, 16
  • [22] Attack against Layered Defense
    Morozov, V. V.
    DOKLADY MATHEMATICS, 2023, 108 (SUPPL 1) : S128 - S132
  • [23] DEFENSE AGAINST BOMBER ATTACK
    ENGLISH, RD
    BOLEF, DI
    SCIENTIFIC AMERICAN, 1973, 229 (02) : 11 - 19
  • [24] Attack against Layered Defense
    V. V. Morozov
    Doklady Mathematics, 2023, 108 : S128 - S132
  • [25] Variance-Based Feature Importance in Neural Networks
    de Sa, Claudio Rebelo
    DISCOVERY SCIENCE (DS 2019), 2019, 11828 : 306 - 315
  • [26] On variance-based sub typing for parametric types
    Igarashi, A
    Viroli, M
    ECOOP 2002 - OBJECT-ORIENTED PROGRAMMING, 2002, 2374 : 441 - 469
  • [27] Variance-based uncertainty relations for incompatible observables
    Chen, Bin
    Cao, Ning-Ping
    Fei, Shao-Ming
    Long, Gui-Lu
    QUANTUM INFORMATION PROCESSING, 2016, 15 (09) : 3909 - 3917
  • [28] Variance-based sensitivity analyses of piezoelectric models
    Lahmer, T.
    Ilg, J.
    Lerch, R.
    2015, Tech Science Press (106): : 105 - 126
  • [29] Defense against poison gas in air raids
    不详
    JOURNAL OF THE AMERICAN MEDICAL ASSOCIATION, 1938, 110 : 57 - 57
  • [30] Nonparametric variance-based methods of assessing uncertainty importance
    McKay, MD
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 1997, 57 (03) : 267 - 279