Defending Against Backdoor Attacks via Region Growing and Diffusion Model
作者:Haoquan Wang, Shengbo Chen, Xijun Wang, Hong Rao, Yong Chen · 年份:2024 · DOI:10.1109/icme57554.2024.10687962 · 研究领域:Network Security and Intrusion Detection
The widespread adoption of deep neural networks (DNNs) is a testament to their profound impact on various domains. However, they are vulnerable to backdoor attacks. Previous defense strategies suffer from requiring additional prior knowledge or performance decreases. To tackle these challenges, we propose a new method to mitigate the impact of backdoor triggers. Specifically, we first devise a simple yet effective detection mechanism based on the region growing algorithm, which enables the identification of triggers within training data without necessitating prior knowledge. Then, we leverage the diffusion model to eliminate the inserted triggers while recovering the data information at the triggers’ locations. Finally, the processed data are fed into the current model for label recovery. Extensive experiments on the CIFAR10, Tiny Imagenet, and GTSRB datasets demonstrate that our method can defend against backdoor attacks effectively and surpasses the state-of-the-art defenses in terms of both main task accuracy (ACC) and backdoor task attack success rate (ASR).