跳到主要导航 跳到搜索 跳到主要内容

Redeem Myself: Purifying Backdoors in Deep Learning Models using Self Attention Distillation

  • Xueluan Gong
  • , Yanjiao Chen
  • , Wang Yang
  • , Qian Wang
  • , Yuzhe Gu
  • , Huayang Huang
  • , Chao Shen
  • Wuhan University
  • Zhejiang University

科研成果: 书/报告/会议事项章节会议稿件同行评审

31 引用 (Scopus)

摘要

Recent works have revealed the vulnerability of deep neural networks to backdoor attacks, where a backdoored model orchestrates targeted or untargeted misclassification when activated by a trigger. A line of purification methods (e.g., fine-pruning, neural attention transfer, MCR [69]) have been proposed to remove the backdoor in a model. However, they either fail to reduce the attack success rate of more advanced backdoor attacks or largely degrade the prediction capacity of the model for clean samples. In this paper, we put forward a new purification defense framework, dubbed SAGE, which utilizes self-attention distillation to purge models of backdoors. Unlike traditional attention transfer mechanisms that require a teacher model to supervise the distillation process, SAGE can realize self-purification with a small number of clean samples. To enhance the defense performance, we further propose a dynamic learning rate adjustment strategy that carefully tracks the prediction accuracy of clean samples to guide the learning rate adjustment. We compare the defense performance of SAGE with 6 state-of-the-art defense approaches against 8 backdoor attacks on 4 datasets. It is shown that SAGE can reduce the attack success rate by as much as 90% with less than 3% decrease in prediction accuracy for clean samples. We will open-source our codes upon publication.

源语言英语
主期刊名Proceedings - 44th IEEE Symposium on Security and Privacy, SP 2023
出版商Institute of Electrical and Electronics Engineers Inc.
755-772
页数18
ISBN(电子版)9781665493369
DOI
出版状态已出版 - 2023
活动44th IEEE Symposium on Security and Privacy, SP 2023 - Hybrid, San Francisco, 美国
期限: 22 5月 202325 5月 2023

出版系列

姓名Proceedings - IEEE Symposium on Security and Privacy
2023-May
ISSN(印刷版)1081-6011

会议

会议44th IEEE Symposium on Security and Privacy, SP 2023
国家/地区美国
Hybrid, San Francisco
时期22/05/2325/05/23

学术指纹

探究 'Redeem Myself: Purifying Backdoors in Deep Learning Models using Self Attention Distillation' 的科研主题。它们共同构成独一无二的指纹。

引用此