PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 8, 2026International Journal of Pattern Recognition and Artificial Intelligence0 citations

PulsePoison Backdoor: A Stealthy Data Poisoning Attack Against Dataset Distillation

View Full Paper
WLWang LiFZFeifei ZhuJLJunqing Le

Key Points

  • The research aims to develop a stealthy data poisoning attack within dataset distillation processes.
  • Introduced PulsePoison Backdoor (PPB) using Gaussian pulse noise as a trigger.
  • Embedded triggers into luminance channels of clean samples using linear superposition.
  • Conducted experiments on standard benchmarks to assess efficacy against distillation techniques.
  • PPB achieved high attack success rates with minimal impact on benign model performance.
  • PPB outperformed existing backdoor strategies in stealthiness and robustness.
  • Demonstrated effectiveness against data enhancement-based defenses.

Abstract

Deep neural networks (DNNs) have achieved remarkable performance in various domains but rely heavily on large-scale, high-quality datasets, resulting in substantial storage, computation, and energy costs. Dataset distillation has been introduced as a promising technique that condenses large-scale datasets into smaller synthetic counterparts while still maintaining model accuracy, making it especially valuable in resource-limited environments. Currently, dataset distillation still faces significant security risks—even in some scenarios where the attacker can only control the original training data and cannot interfere with the distillation process, attacks remain possible. However, existing backdoor attacks in this scenario often fail because triggers can be removed or become obvious during distillation. Towards this end, we propose PulsePoison Backdoor (PPB), a poisoning-based attack leveraging Gaussian pulse noise as an implicit trigger. PPB stealthily embeds triggers via linear superposition into luminance channels of clean samples, without interfering with the distillation pipeline. This design ensures that triggers survive the distillation process while remaining visually benign in both pre- and post-distillation data. Experiments with standard benchmarks and dataset distillation techniques demonstrate that PPB achieves high attack success with negligible impact on benign performance and remains effective against common data enhancement-based defenses, outperforming existing backdoor strategies in both stealthiness and robustness.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Li et al. (2026) studied this question.

synapsesocial.com/papers/69d5f03374eaea4b11a79b4ehttps://doi.org/10.1142/s0218001426500205
Ask AI
Helpful
Bookmark
Share
View Full Paper