BDEL: A Backdoor Attack Defense Method Based on Ensemble Learning

被引:0
|
作者
Xing, Zhihuan [1 ]
Lan, Yuqing [2 ]
Yu, Yin [3 ]
Cao, Yong [2 ,4 ]
Yang, Xiaoyi [2 ]
Yu, Yichun [1 ,2 ,3 ,4 ]
Yu, Dan [4 ]
机构
[1] Beihang Univ, Sch Comp Sci & Engn, Beijing 100191, Peoples R China
[2] Beihang Univ, Sch Software, Beijing 100191, Peoples R China
[3] Bejing Inst Technol, Sch Cyberspace Sci & Technol, Beijing 100081, Peoples R China
[4] China Stand Intelligent Secur Co Ltd, Beijing 100097, Peoples R China
关键词
Security of deep learning; Backdoor attacks; Ensemble learning; NEURAL-NETWORKS;
D O I
10.1007/978-981-96-0116-5_18
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural networks (DNNs) are susceptible to backdoor attacks. Previous researches have demonstrated the challenges in both removing poisoned samples from compromised datasets and repairing contaminated models. These difficulties arise as attackers employ adaptive strategies, enhancing the stealthiness of their attacks and thereby evading detection by defenders. To address these challenges, we propose BDEL, a defense method based on ensemble learning, aimed at enhancing the model intrinsic robustness against backdoor attacks. BDEL focuses on strengthening the model directly, thus avoiding the need for assumptions about the attackers. In addition, BDEL does not require the retention of a clean dataset and is compatible with any existing DNN. Specifically, we construct random subsets from the original dataset and train individual base classifiers on these subsets, each equipped with a different network architecture. During the training process of these base classifiers, a self-ensembling strategy is employed to enhance the intrinsic robustness of the model. To the best of our knowledge, we are the first to propose a method to enhance model robustness against backdoor attacks through self-ensembling. We evaluated BDEL against various types of backdoor attacks. The results demonstrate that BDEL is effective in defending against these attacks and achieves state-of-the-art performance.
引用
收藏
页码:221 / 235
页数:15
相关论文
共 50 条
  • [21] A Textual Backdoor Defense Method Based on Deep Feature Classification
    Shao, Kun
    Yang, Junan
    Hu, Pengjiang
    Li, Xiaoshuai
    ENTROPY, 2023, 25 (02)
  • [22] Sniper Backdoor: Single Client Targeted Backdoor Attack in Federated Learning
    Abad, Gorka
    Paguada, Servio
    Ersoy, Oguzhan
    Picek, Stjepan
    Ramirez-Duran, Victor Julio
    Urbieta, Aitor
    2023 IEEE CONFERENCE ON SECURE AND TRUSTWORTHY MACHINE LEARNING, SATML, 2023, : 377 - 391
  • [23] Object-free backdoor attack and defense on semantic segmentation
    Mao, Jiaoze
    Qian, Yaguan
    Huang, Jianchang
    Lian, Zejie
    Tao, Renhui
    Wang, Bin
    Wang, Wei
    Yao, Tengteng
    COMPUTERS & SECURITY, 2023, 132
  • [24] Towards Backdoor Attack on Deep Learning based Time Series Classification
    Ding, Daizong
    Zhang, Mi
    Huang, Yuanmin
    Pan, Xudong
    Feng, Fuli
    Jiang, Erling
    Yang, Min
    2022 IEEE 38TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE 2022), 2022, : 1274 - 1287
  • [25] Federated Learning Backdoor Attack Scheme Based on Generative Adversarial Network
    Chen D.
    Fu A.
    Zhou C.
    Chen Z.
    Fu, Anmin (fuam@njust.edu.cn); Fu, Anmin (fuam@njust.edu.cn), 1600, Science Press (58): : 2364 - 2373
  • [26] Dual-domain based backdoor attack against federated learning
    Li, Guorui
    Chang, Runxing
    Wang, Ying
    Wang, Cong
    NEUROCOMPUTING, 2025, 623
  • [27] Knowledge Distillation Based Defense for Audio Trigger Backdoor in Federated Learning
    Chen, Yu-Wen
    Ke, Bo-Hsu
    Chen, Bo-Zhong
    Chiu, Si-Rong
    Tu, Chun-Wei
    Kuo, Jian-Jhih
    IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 4271 - 4276
  • [28] Successive Interference Cancellation Based Defense for Trigger Backdoor in Federated Learning
    Chen, Yu-Wen
    Ke, Bo-Hsu
    Chen, Bo-Zhong
    Chiu, Si-Rong
    Tu, Chun-Wei
    Kuo, Jian-Jhih
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 26 - 32
  • [29] Backdoor Defense via Deconfounded Representation Learning
    Zhang, Zaixi
    Liu, Qi
    Wang, Zhicai
    Lu, Zepu
    Hu, Qingyong
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 12228 - 12238
  • [30] Poster: Backdoor Attack on Extreme Learning Machines
    Tajalli, Behrad
    Abad, Gorka
    Picek, Stjepan
    PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023, 2023, : 3588 - 3590