Purifier: Plug-and-play Backdoor Mitigation for Pre-trained Models Via Anomaly Activation Suppression

后门 计算机科学 稳健性(进化) 推论 计算机安全 人工智能 生物化学 基因 化学
作者
Xiaoyu Zhang,Yulin Jin,Tao Wang,Jian Lou,Xiaofeng Chen
标识
DOI:10.1145/3503161.3548065
摘要

Pre-trained models have been widely adopted in deep learning development, benefiting the fine-tuning of downstream user-specific tasks with enormous computation saving. However, backdoor attacks pose severe security threat to the subsequent models built upon compromised pre-trained models, which call for effective countermeasures to mitigate the backdoor threat before deploying the victim models to safety-critical applications. This paper proposesPurifier : a novel backdoor mitigation framework for pre-trained models via suppressing anomaly activation.Purifier is motivated by the observation that, for backdoor triggers, anomaly activation patterns exist across different perspectives (e.g., channel-wise, cube-wise, and feature-wise), featuring different degrees of granularity. More importantly, choosing to suppress at the right granularity is vital to robustness and accuracy. To this end,Purifier is capable of defending against diverse types of backdoor triggers without any prior knowledge of the backdoor attacks, meanwhile featuring a convenient and flexible characteristic during deployment, i.e., plug-and-play-able. The extensive experimental results show, against a series of state-of-the-art mainstream attacks, thatPurifier performs better in terms of both defense effectiveness and model inference accuracy on clean examples than the state-of-the-art methods. Our code and Appendix can be found in \urlgithub.com/RUIYUN-ML/Purifier.

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
PDF的下载单位、IP信息已删除 (2025-6-4)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
kuryu完成签到,获得积分10
2秒前
杨旭完成签到,获得积分10
2秒前
2秒前
2秒前
DRHSK完成签到,获得积分20
3秒前
可爱的函函应助短兵相接采纳,获得10
3秒前
3秒前
香查朵完成签到,获得积分10
3秒前
4秒前
Hello应助潇洒的冰烟采纳,获得10
4秒前
英俊的铭应助清秀夏寒采纳,获得10
4秒前
DRHSK发布了新的文献求助10
5秒前
一减完成签到 ,获得积分10
6秒前
思源应助大胆诗云采纳,获得10
6秒前
ggg完成签到 ,获得积分10
6秒前
Orange应助666plus采纳,获得10
7秒前
shyong发布了新的文献求助100
7秒前
可爱的函函应助ZZY采纳,获得10
7秒前
桃桃甜筒发布了新的文献求助10
7秒前
雪糕完成签到 ,获得积分10
7秒前
一一完成签到,获得积分10
8秒前
甜甜甜发布了新的文献求助30
8秒前
丘比特应助yangfuning采纳,获得10
8秒前
李健应助单身的傲晴采纳,获得10
8秒前
8秒前
8秒前
巴黎快乐发布了新的文献求助10
8秒前
maomao完成签到,获得积分10
8秒前
8秒前
9秒前
9秒前
闪闪的夜柳完成签到,获得积分10
9秒前
废寝忘食发布了新的文献求助10
10秒前
宏韬完成签到,获得积分10
10秒前
这篇文献真好完成签到,获得积分10
10秒前
李升洋完成签到 ,获得积分10
11秒前
hhhh_xt发布了新的文献求助10
11秒前
11秒前
陈丰滢发布了新的文献求助10
11秒前
cecilycen完成签到,获得积分10
12秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Predation in the Hymenoptera: An Evolutionary Perspective 1800
List of 1,091 Public Pension Profiles by Region 1561
Binary Alloy Phase Diagrams, 2nd Edition 1200
Holistic Discourse Analysis 600
Beyond the sentence: discourse and sentential form / edited by Jessica R. Wirth 600
Red Book: 2024–2027 Report of the Committee on Infectious Diseases 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 生物化学 物理 纳米技术 计算机科学 内科学 化学工程 复合材料 物理化学 基因 遗传学 催化作用 冶金 量子力学 光电子学
热门帖子
关注 科研通微信公众号,转发送积分 5511083
求助须知:如何正确求助?哪些是违规求助? 4605828
关于积分的说明 14495709
捐赠科研通 4540975
什么是DOI,文献DOI怎么找? 2488254
邀请新用户注册赠送积分活动 1470413
关于科研通互助平台的介绍 1442806