Skip to main navigation Skip to search Skip to main content

SifterNet: Model-Agnostic Defense against Backdoor Attack in Vision Large Model

  • Shaoye Luo
  • , Xinxin Fan*
  • , Quanliang Jing
  • , Men Niu
  • , Chi Lin
  • , Yunfeng Lu
  • *Corresponding author for this work
  • University of Chinese Academy of Sciences
  • Dalian University of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Vision models have been applied into urban computing, vision-language navigation, intelligent transportation, etc. Nevertheless, various convolution neural networks (CNN)-based vision models, or even the recently-developed vision Transformer-based large models all encounter security and privacy issues. In this paper, aiming at resisting backdoor attacks in these vision models, we proposes a generalized and model-agnostic trigger-purification approach resorting to the classic Ising model in physics. To date, existing trigger detection/removal studies usually require to know the detailed knowledge of target model in advance, access to a large number of clean samples or even model-retraining authorization, which brings the huge inconvenience for practical applications, especially in case of inaccessibility to the target model. Thereby, an ideal countermeasure ought to eliminate the implanted trigger without regarding whatever the target models are. To this end, a lightweight and black-box defense approach SifterNet is proposed through leveraging the memorization-association functionality of Hopfield network, by which the triggers of input samples can be effectively purified in a proper manner. The main novelty of our proposed approach lies in the introduction of ideology of Ising model. A set of experiments also validate the effectiveness of our approach in terms of proper trigger purification and high accuracy achievement, and compared to the state-of-the-art baselines, our proposed SiferNet has a significant superior performance under five popular backdoor attacks.

Original languageEnglish
Title of host publicationBuildSys 2025 - Proceedings of the 2025 the 12th ACM International Conference on Systems for Energy-Efficient Buildings, Cities, and Transportation
PublisherAssociation for Computing Machinery, Inc
Pages389-393
Number of pages5
ISBN (Electronic)9798400719455
DOIs
StatePublished - 11 Nov 2025
Event12th ACM International Conference on Systems for Energy-Efficient Buildings, Cities, and Transportation, BuildSys 2025 - Golden, United States
Duration: 19 Nov 202521 Nov 2025

Publication series

NameBuildSys 2025 - Proceedings of the 2025 the 12th ACM International Conference on Systems for Energy-Efficient Buildings, Cities, and Transportation

Conference

Conference12th ACM International Conference on Systems for Energy-Efficient Buildings, Cities, and Transportation, BuildSys 2025
Country/TerritoryUnited States
CityGolden
Period19/11/2521/11/25

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 7 - Affordable and Clean Energy
    SDG 7 Affordable and Clean Energy
  2. SDG 11 - Sustainable Cities and Communities
    SDG 11 Sustainable Cities and Communities

Keywords

  • backdoor defense
  • trigger purification
  • vision LLMs

Fingerprint

Dive into the research topics of 'SifterNet: Model-Agnostic Defense against Backdoor Attack in Vision Large Model'. Together they form a unique fingerprint.

Cite this