Knowledge-Driven Backdoor Removal in Deep Neural Networks via Reinforcement Learning

被引:0
|
作者
Song, Jiayin [1 ]
Li, Yike [1 ]
Tian, Yunzhe [1 ]
Wu, Xingyu [1 ]
Li, Qiong [1 ]
Tong, Endong [1 ,2 ]
Niu, Wenjia [1 ]
Zhang, Zhenguo [3 ]
Liu, Jiqiang [1 ]
机构
[1] Beijing Jiaotong Univ, Beijing Key Lab Secur & Privacy Intelligent Trans, Beijing 100044, Peoples R China
[2] Beijing Jiaotong Univ, Tangshan Res Inst, Tangshan 063000, Peoples R China
[3] Hebei Boshilin Technol Dev Co Ltd, Shijiazhuang, Hebei, Peoples R China
基金
中国国家自然科学基金;
关键词
Backdoor Removal; Reinforcement Learning; Neuron Activate; Backdoor Attack; Deep Learning;
D O I
10.1007/978-981-97-5498-4_26
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Backdoor attacks have become a major security threat to deep neural networks (DNNs), promoting significant studies in backdoor removal to mitigate these attacks. However, existing backdoor removal methods often work independently and struggle to generalize across various attacks, which limits their effectiveness when the specific methods used by attackers are unknown. To effectively defend against multiple backdoor attacks, in this paper, we propose the Reinforcement Learning-based Backdoor Removal (RLBR) framework, which integrates multiple defense strategies and dynamically switches various defense methods during the removal process. Driven by the knowledge we observed that a) neuron activation patterns vary significantly under different attacks, and b) these patterns dynamically change during the removal process, we take the neuron activation pattern of the poisoned models as the environment state in the RLBR framework. Besides, we evaluate the defense effectiveness as rewards to guide the selection of optimal defense strategy at each decision point. Through extensive experiments against six state-of-the-art backdoor attacks on two benchmark datasets, RLBR improved defensive performance by 6.91% while maintaining an accuracy of 92.63% on clean datasets, compared to seven baseline backdoor defense methods.
引用
收藏
页码:336 / 348
页数:13
相关论文
共 50 条
  • [21] Latent Backdoor Attacks on Deep Neural Networks
    Yao, Yuanshun
    Li, Huiying
    Zheng, Haitao
    Zhao, Ben Y.
    PROCEEDINGS OF THE 2019 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'19), 2019, : 2041 - 2055
  • [22] TrojDRL: Evaluation of Backdoor Attacks on Deep Reinforcement Learning
    Kiourti, Panagiota
    Wardega, Kacper
    Jha, Susmit
    Li, Wenchao
    PROCEEDINGS OF THE 2020 57TH ACM/EDAC/IEEE DESIGN AUTOMATION CONFERENCE (DAC), 2020,
  • [23] Camera Identification Based on Domain Knowledge-Driven Deep-Task Learning
    Ding, Xinghao
    Chen, Yunshu
    Tang, Zhen
    Huang, Yue
    IEEE ACCESS, 2019, 7 : 25878 - 25890
  • [24] Managing innovation networks in the knowledge-driven economy
    Bullinger, HJ
    Auernhammer, K
    Gomeringer, A
    INTERNATIONAL JOURNAL OF PRODUCTION RESEARCH, 2004, 42 (17) : 3337 - 3353
  • [25] Transparency and Explanation in Deep Reinforcement Learning Neural Networks
    Iyer, Rahul
    Li, Yuezhang
    Li, Huao
    Lewis, Michael
    Sundar, Ramitha
    Sycara, Katia
    PROCEEDINGS OF THE 2018 AAAI/ACM CONFERENCE ON AI, ETHICS, AND SOCIETY (AIES'18), 2018, : 144 - 150
  • [26] Adaptive Knowledge Driven Regularization for Deep Neural Networks
    Luo, Zhaojing
    Cai, Shaofeng
    Cui, Can
    Ooi, Beng Chin
    Yang, Yang
    THIRTY-FIFTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THIRTY-THIRD CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE AND THE ELEVENTH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2021, 35 : 8810 - 8818
  • [27] Learning method objects for knowledge-driven environments
    Heinz, I
    Suter-Seuling, U
    KNOWLEDGE-BASED INTELLIGNET INFORMATION AND ENGINEERING SYSTEMS, PT 2, PROCEEDINGS, 2003, 2774 : 1202 - 1207
  • [28] Incorporating biological prior knowledge for Bayesian learning via maximal knowledge-driven information priors
    Shahin Boluki
    Mohammad Shahrokh Esfahani
    Xiaoning Qian
    Edward R Dougherty
    BMC Bioinformatics, 18
  • [29] Incorporating biological prior knowledge for Bayesian learning via maximal knowledge-driven information priors
    Boluki, Shahin
    Esfahani, Mohammad Shahrokh
    Qian, Xiaoning
    Dougherty, Edward R.
    BMC BIOINFORMATICS, 2017, 18
  • [30] Cluster knowledge-driven vertical federated learning
    Yin, Zilong
    Zhao, Xiaoli
    Wang, Haoyu
    Zhang, Xin
    Guo, Xin
    Fang, Zhijun
    JOURNAL OF SUPERCOMPUTING, 2024, 80 (14): : 20229 - 20252