PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
March 18, 20240 citationsOpen Access

Diffusion Denoising as a Certified Defense against Clean-label Poisoning

View Full Paper
SHSanghyun HongNCNicholas CarliniAKAlexey Kurakin

Key Points

Key points are not available for this paper at this time.

Abstract

We present a certified defense to clean-label poisoning attacks. These attacks work by injecting a small number of poisoning samples (e. g. , 1%) that contain p-norm bounded adversarial perturbations into the training data to induce a targeted misclassification of a test-time input. Inspired by the adversarial robustness achieved by denoised smoothing, we show how an off-the-shelf diffusion model can sanitize the tampered training data. We extensively test our defense against seven clean-label poisoning attacks and reduce their attack success to 0-16% with only a negligible drop in the test time accuracy. We compare our defense with existing countermeasures against clean-label poisoning, showing that the defense reduces the attack success the most and offers the best model utility. Our results highlight the need for future work on developing stronger clean-label attacks and using our certified yet practical defense as a strong baseline to evaluate these attacks.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Hong et al. (2024) studied this question.

synapsesocial.com/papers/68e73a7cb6db6435876b3addhttps://doi.org/10.48550/arxiv.2403.11981
Ask AI
Helpful
Bookmark
Share
View Full Paper