Deep neural networks (DNNs) are vulnerable to backdoor attacks. Previous works have shown it extremely challenging to unlearn the undesired backdoor behavior from the network, since the entire network can be affected by the backdoor samples. In this paper, we propose a brand-new backdoor defense strategy, which makes it much easier to remove the harmful influence of backdoor samples from the model. Our defense strategy, , consists of two stages. In the first stage, we bait and trap the backdoors in a small and easy-to-replace subnetwork. Specifically, we add an auxiliary image reconstruction head on top of the stem network shared with a light-weighted classification head. The intuition is that the auxiliary image reconstruction task encourages the stem network to keep sufficient low-level visual features that are hard to learn but semantically correct, instead of overfitting to the easy-to-learn but semantically incorrect backdoor correlations. As a result, when trained on backdoored datasets, the backdoors are easily baited towards the unprotected classification head, since it is much more vulnerable than the shared stem, leaving the stem network hardly poisoned. In the second stage, we replace the poisoned light-weighted classification head with an untainted one, by re-training it from scratch only on a small holdout dataset with clean samples, while fixing the stem network. As a result, both the stem and the classification head in the final network are hardly affected by backdoor training samples. We evaluate our method against ten different backdoor attacks. Our method outperforms previous state-of-the-art methods by up to 20.57%, 9.80%, and 13.72% attack success rate and on-average 3.14%, 1.80%, and 1.21% clean classification accuracy on CIFAR10, GTSRB, and ImageNet-12, respectively. Code is available at https://github.com/VITA-Group/Trap-and-Replace-Backdoor-Defense.

Download full-text PDF

Source
http://www.ncbi.nlm.nih.gov/pmc/articles/PMC10115557PMC

Publication Analysis

Top Keywords

stem network
16
classification head
16
backdoor attacks
12
backdoor
9
easy-to-replace subnetwork
8
network backdoor
8
backdoor samples
8
defense strategy
8
auxiliary image
8
image reconstruction
8

Similar Publications

Bone homeostasis encompasses two interrelated aspects: bone remodeling and cartilage metabolism. Disruption of bone homeostasis can lead to the development of metabolic bone diseases such as osteoporosis and osteoarthritis. The maintenance of bone homeostasis is a complex process that does not solely rely on the functions of the bone tissue itself.

View Article and Find Full Text PDF

is a traditional Chinese medicinal herb rich in various bioactive secondary metabolites, such as alkaloids and flavonoids, and exhibits remarkable resistance to abiotic stress. The WRKY transcription factor (TF) family is one of the largest plant-specific TF families and plays a crucial role in plant growth, development, and responses to abiotic stress. However, a comprehensive genome-wide analysis of the WRKY gene family in has not yet been conducted.

View Article and Find Full Text PDF

encodes a UDP-galactose transporter essential for glycosylation of proteins and galactosylation of lipids and glycosaminoglycans. Germline genetic variants have been identified in congenital disorders of glycosylation and somatic variants have been linked to intractable epilepsy associated with malformations of cortical development. However, the functional consequences of these pathogenic variants on brain development and network integrity remain elusive.

View Article and Find Full Text PDF

Oligodendrocytes are the myelinating cells of the central nervous system. Regulation of the early stages of oligodendrocyte development is critical to the function of the cell. Specifically, myelin sheath formation is an energetically demanding event that requires precision, as alterations may lead to dysmyelination.

View Article and Find Full Text PDF

Comprehensive analysis of scRNA-seq and bulk RNA-seq reveals the non-cardiomyocytes heterogeneity and novel cell populations in dilated cardiomyopathy.

J Transl Med

January 2025

State Key Laboratory of Cardiovascular Diseases and Medical Innovation Center, School of Medicine, Shanghai East Hospital, Tongji University, Shanghai, 200120, China.

Background: Dilated cardiomyopathy (DCM) is one of the most common causes of heart failure. Infiltration and alterations in non-cardiomyocytes of the human heart involve crucially in the occurrence of DCM and associated immunotherapeutic approaches.

Methods: We constructed a single-cell transcriptional atlas of DCM and normal patients.

View Article and Find Full Text PDF

Want AI Summaries of new PubMed Abstracts delivered to your In-box?

Enter search terms and have AI summaries delivered each week - change queries or unsubscribe any time!