BDEL: A Backdoor Attack Defense Method Based on Ensemble Learning

被引:0
|
作者
Xing, Zhihuan [1 ]
Lan, Yuqing [2 ]
Yu, Yin [3 ]
Cao, Yong [2 ,4 ]
Yang, Xiaoyi [2 ]
Yu, Yichun [1 ,2 ,3 ,4 ]
Yu, Dan [4 ]
机构
[1] Beihang Univ, Sch Comp Sci & Engn, Beijing 100191, Peoples R China
[2] Beihang Univ, Sch Software, Beijing 100191, Peoples R China
[3] Bejing Inst Technol, Sch Cyberspace Sci & Technol, Beijing 100081, Peoples R China
[4] China Stand Intelligent Secur Co Ltd, Beijing 100097, Peoples R China
关键词
Security of deep learning; Backdoor attacks; Ensemble learning; NEURAL-NETWORKS;
D O I
10.1007/978-981-96-0116-5_18
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural networks (DNNs) are susceptible to backdoor attacks. Previous researches have demonstrated the challenges in both removing poisoned samples from compromised datasets and repairing contaminated models. These difficulties arise as attackers employ adaptive strategies, enhancing the stealthiness of their attacks and thereby evading detection by defenders. To address these challenges, we propose BDEL, a defense method based on ensemble learning, aimed at enhancing the model intrinsic robustness against backdoor attacks. BDEL focuses on strengthening the model directly, thus avoiding the need for assumptions about the attackers. In addition, BDEL does not require the retention of a clean dataset and is compatible with any existing DNN. Specifically, we construct random subsets from the original dataset and train individual base classifiers on these subsets, each equipped with a different network architecture. During the training process of these base classifiers, a self-ensembling strategy is employed to enhance the intrinsic robustness of the model. To the best of our knowledge, we are the first to propose a method to enhance model robustness against backdoor attacks through self-ensembling. We evaluated BDEL against various types of backdoor attacks. The results demonstrate that BDEL is effective in defending against these attacks and achieves state-of-the-art performance.
引用
收藏
页码:221 / 235
页数:15
相关论文
共 50 条
  • [31] A General Backdoor Attack to Graph Neural Networks Based on Explanation Method
    Chen, Luyao
    Yan, Na
    Zhang, Boyang
    Wang, Zhaoyang
    Wen, Yu
    Hu, Yanfei
    2022 IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS, TRUSTCOM, 2022, : 759 - 768
  • [32] Adversarial defense method based on ensemble learning for modulation signal intelligent recognition
    Han, Chao
    Qin, Ruoxi
    Wang, Linyuan
    Cui, Weijia
    Chen, Jian
    Yan, Bin
    WIRELESS NETWORKS, 2023, 29 (07) : 2967 - 2980
  • [33] Adversarial defense method based on ensemble learning for modulation signal intelligent recognition
    Chao Han
    Ruoxi Qin
    Linyuan Wang
    Weijia Cui
    Jian Chen
    Bin Yan
    Wireless Networks, 2023, 29 : 2967 - 2980
  • [34] DDoS Attack Identification and Defense using SDN based on Machine Learning Method
    Yang Lingfeng
    Zhao Hui
    2018 15TH INTERNATIONAL SYMPOSIUM ON PERVASIVE SYSTEMS, ALGORITHMS AND NETWORKS (I-SPAN 2018), 2018, : 166 - 170
  • [35] BayBFed: Bayesian Backdoor Defense for Federated Learning
    Kumari, Kavita
    Rieger, Phillip
    Fereidooni, Hossein
    Jadliwala, Murtuza
    Sadeghi, Ahmad-Reza
    2023 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, SP, 2023, : 737 - 754
  • [36] A backdoor attack method based on target feature enhanced generative network
    Zhao, Changfei
    Xiao, Tao
    Deng, Xinyang
    Jiang, Wen
    INFORMATION SCIENCES, 2025, 698
  • [37] Backdoor attack and defense in federated generative adversarial network-based medical image synthesis
    Jin, Ruinan
    Li, Xiaoxiao
    MEDICAL IMAGE ANALYSIS, 2023, 90
  • [38] Backdoor Attack Against Deep Learning-Based Autonomous Driving with Fogging
    Liu, Jianming
    Luo, Li
    Wang, Xueyan
    ARTIFICIAL INTELLIGENCE AND ROBOTICS, ISAIR 2022, PT II, 2022, 1701 : 247 - 256
  • [39] An Attack Detection Method for Self-Powered Sensor IoTs Based on Ensemble Learning
    Wang, Huan
    Wang, Yan
    Zhang, Haifeng
    Yang, Shuhong
    Peng, Yong
    Wang, Zhe
    IEEE SENSORS JOURNAL, 2023, 23 (18) : 20663 - 20671
  • [40] Distributed Swift and Stealthy Backdoor Attack on Federated Learning
    Sundar, Agnideven Palanisamy
    Li, Feng
    Zou, Xukai
    Gao, Tianchong
    2022 IEEE INTERNATIONAL CONFERENCE ON NETWORKING, ARCHITECTURE AND STORAGE (NAS), 2022, : 193 - 200