跳到主要导航 跳到搜索 跳到主要内容

SifterNet: Model-Agnostic Defense against Backdoor Attack in Vision Large Model

  • Shaoye Luo
  • , Xinxin Fan*
  • , Quanliang Jing
  • , Men Niu
  • , Chi Lin
  • , Yunfeng Lu
  • *此作品的通讯作者
  • University of Chinese Academy of Sciences
  • Dalian University of Technology

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Vision models have been applied into urban computing, vision-language navigation, intelligent transportation, etc. Nevertheless, various convolution neural networks (CNN)-based vision models, or even the recently-developed vision Transformer-based large models all encounter security and privacy issues. In this paper, aiming at resisting backdoor attacks in these vision models, we proposes a generalized and model-agnostic trigger-purification approach resorting to the classic Ising model in physics. To date, existing trigger detection/removal studies usually require to know the detailed knowledge of target model in advance, access to a large number of clean samples or even model-retraining authorization, which brings the huge inconvenience for practical applications, especially in case of inaccessibility to the target model. Thereby, an ideal countermeasure ought to eliminate the implanted trigger without regarding whatever the target models are. To this end, a lightweight and black-box defense approach SifterNet is proposed through leveraging the memorization-association functionality of Hopfield network, by which the triggers of input samples can be effectively purified in a proper manner. The main novelty of our proposed approach lies in the introduction of ideology of Ising model. A set of experiments also validate the effectiveness of our approach in terms of proper trigger purification and high accuracy achievement, and compared to the state-of-the-art baselines, our proposed SiferNet has a significant superior performance under five popular backdoor attacks.

源语言英语
主期刊名BuildSys 2025 - Proceedings of the 2025 the 12th ACM International Conference on Systems for Energy-Efficient Buildings, Cities, and Transportation
出版商Association for Computing Machinery, Inc
389-393
页数5
ISBN(电子版)9798400719455
DOI
出版状态已出版 - 11 11月 2025
活动12th ACM International Conference on Systems for Energy-Efficient Buildings, Cities, and Transportation, BuildSys 2025 - Golden, 美国
期限: 19 11月 202521 11月 2025

出版系列

姓名BuildSys 2025 - Proceedings of the 2025 the 12th ACM International Conference on Systems for Energy-Efficient Buildings, Cities, and Transportation

会议

会议12th ACM International Conference on Systems for Energy-Efficient Buildings, Cities, and Transportation, BuildSys 2025
国家/地区美国
Golden
时期19/11/2521/11/25

联合国可持续发展目标

此成果有助于实现下列可持续发展目标:

  1. 可持续发展目标 7 - 经济适用的清洁能源
    可持续发展目标 7 经济适用的清洁能源
  2. 可持续发展目标 11 - 可持续城市和社区
    可持续发展目标 11 可持续城市和社区

学术指纹

探究 'SifterNet: Model-Agnostic Defense against Backdoor Attack in Vision Large Model' 的科研主题。它们共同构成独一无二的学术指纹。

引用此