BDEL: A Backdoor Attack Defense Method Based on Ensemble Learning

被引:0
|
作者
Xing, Zhihuan [1 ]
Lan, Yuqing [2 ]
Yu, Yin [3 ]
Cao, Yong [2 ,4 ]
Yang, Xiaoyi [2 ]
Yu, Yichun [1 ,2 ,3 ,4 ]
Yu, Dan [4 ]
机构
[1] Beihang Univ, Sch Comp Sci & Engn, Beijing 100191, Peoples R China
[2] Beihang Univ, Sch Software, Beijing 100191, Peoples R China
[3] Bejing Inst Technol, Sch Cyberspace Sci & Technol, Beijing 100081, Peoples R China
[4] China Stand Intelligent Secur Co Ltd, Beijing 100097, Peoples R China
关键词
Security of deep learning; Backdoor attacks; Ensemble learning; NEURAL-NETWORKS;
D O I
10.1007/978-981-96-0116-5_18
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural networks (DNNs) are susceptible to backdoor attacks. Previous researches have demonstrated the challenges in both removing poisoned samples from compromised datasets and repairing contaminated models. These difficulties arise as attackers employ adaptive strategies, enhancing the stealthiness of their attacks and thereby evading detection by defenders. To address these challenges, we propose BDEL, a defense method based on ensemble learning, aimed at enhancing the model intrinsic robustness against backdoor attacks. BDEL focuses on strengthening the model directly, thus avoiding the need for assumptions about the attackers. In addition, BDEL does not require the retention of a clean dataset and is compatible with any existing DNN. Specifically, we construct random subsets from the original dataset and train individual base classifiers on these subsets, each equipped with a different network architecture. During the training process of these base classifiers, a self-ensembling strategy is employed to enhance the intrinsic robustness of the model. To the best of our knowledge, we are the first to propose a method to enhance model robustness against backdoor attacks through self-ensembling. We evaluated BDEL against various types of backdoor attacks. The results demonstrate that BDEL is effective in defending against these attacks and achieves state-of-the-art performance.
引用
收藏
页码:221 / 235
页数:15
相关论文
共 50 条
  • [41] Chronic Poisoning: Backdoor Attack against Split Learning
    Yu, Fangchao
    Zeng, Bo
    Zhao, Kai
    Pang, Zhi
    Wang, Lina
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 15, 2024, : 16531 - 16538
  • [42] Federated learning backdoor attack detection with persistence diagram
    Ma, Zihan
    Gao, Tianchong
    COMPUTERS & SECURITY, 2024, 136
  • [43] AdvDoor: Adversarial Backdoor Attack of Deep Learning System
    Zhang, Quan
    Ding, Yifeng
    Tian, Yongqiang
    Guo, Jianmin
    Yuan, Min
    Jiang, Yu
    ISSTA '21: PROCEEDINGS OF THE 30TH ACM SIGSOFT INTERNATIONAL SYMPOSIUM ON SOFTWARE TESTING AND ANALYSIS, 2021, : 127 - 138
  • [44] FLARE: A Backdoor Attack to Federated Learning with Refined Evasion
    Wang, Qingya
    Wu, Yi
    Xuan, Haojun
    Wu, Huishu
    MATHEMATICS, 2024, 12 (23)
  • [45] Provable Defense against Backdoor Policies in Reinforcement Learning
    Bharti, Shubham Kumar
    Zhang, Xuezhou
    Singla, Adish
    Zhu, Xiaojin
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35 (NEURIPS 2022), 2022,
  • [46] BACKDOORL: Backdoor Attack against Competitive Reinforcement Learning
    Wang, Lun
    Javed, Zaynah
    Wu, Xian
    Guo, Wenbo
    Xing, Xinyu
    Song, Dawn
    PROCEEDINGS OF THE THIRTIETH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, IJCAI 2021, 2021, : 3699 - 3705
  • [47] Backdoor Defense with Colored Patches for Machine Learning Models
    Ikenouchi, Hayato
    Hirose, Haruto
    Uto, Toshiyuki
    2024 INTERNATIONAL TECHNICAL CONFERENCE ON CIRCUITS/SYSTEMS, COMPUTERS, AND COMMUNICATIONS, ITC-CSCC 2024, 2024,
  • [48] Instance-Agnostic and Practical Clean Label Backdoor Attack Method for Deep Learning Based Face Recognition Models
    Kim, Tae-Hoon
    Choi, Seok-Hwan
    Choi, Yoon-Ho
    IEEE ACCESS, 2023, 11 : 144040 - 144050
  • [49] An Invisible Backdoor Attack Based on Semantic Feature
    Chen, Yangming
    Xu, Xiaowei
    Wang, Xiaodong
    Li, Zewen
    Chen, Wenmin
    INTERNATIONAL JOURNAL OF PATTERN RECOGNITION AND ARTIFICIAL INTELLIGENCE, 2025,
  • [50] A defense method against backdoor attacks on neural networks
    Kaviani, Sara
    Shamshiri, Samaneh
    Sohn, Insoo
    EXPERT SYSTEMS WITH APPLICATIONS, 2023, 213