Redeem Myself: Purifying Backdoors in Deep Learning Models using Self Attention Distillation
Xueluan Gong, Yanjiao Chen, Wang Yang, Qian Wang, Yuzhe Gu, Huayang Huang, Chao Shen
Abstract
Recent works have revealed the vulnerability of deep neural networks to backdoor attacks, where a backdoored model orchestrates targeted or untargeted misclassification when activated by a trigger. A line of purification methods (e.g., fine-pruning, neural attention transfer, MCR [69]) have been proposed to remove the backdoor in a model. However, they either fail to reduce the attack success rate of more advanced backdoor attacks or largely degrade the prediction capacity of the model for clean samples. In this paper, we put forward a new purification defense framework, dubbed SAGE, which utilizes self-attention distillation to purge models of backdoors. Unlike traditional attention transfer mechanisms that require a teacher model to supervise the distillation process, SAGE can realize self-purification with a small number of clean samples. To enhance the defense performance, we further propose a dynamic learning rate adjustment strategy that carefully tracks the prediction accuracy of clean samples to guide the learning rate adjustment. We compare the defense performance of SAGE with 6 state-of-the-art defense approaches against 8 backdoor attacks on 4 datasets. It is shown that SAGE can reduce the attack success rate by as much as 90% with less than 3% decrease in prediction accuracy for clean samples. We will open-source our codes upon publication.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers8
- UBA-Inf: Unlearning Activated Backdoor Attack with Influence-Driven CamouflageZirui Huang, Yunlong Mao, Sheng ZhongUSENIX Security 2024 · 16 citations
- Watch Out! Simple Horizontal Class Backdoor Can Trivially Evade DefenseHua Ma, Shang Wang, Yansong Gao, Zhi Zhang et al.CCS 2024 · 7 citations
- FAMOS: Robust Privacy-Preserving Authentication on Payment Apps via Federated Multi-Modal Contrastive LearningYifeng Cai, Ziqi Zhang, Jiaping Gui, Bingyan Liu et al.USENIX Security 2024 · 6 citations
- InverTune: A Backdoor Defense Method for Multimodal Contrastive Learning via Backdoor-Adversarial Correlation AnalysisMengyuan Sun, Yu Li, Yunjie Ge, Yuchen Liu et al.NDSS 2026 · 3 citations
- Lethe: Purifying Backdoored Large Language Models with Knowledge DilutionChen Chen, Yuchen Sun, Jiaxin Gao, Xueluan Gong et al.USENIX Security 2026 · 1 citation
Related papers
- Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural NetworksYige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu et al.ICLR 2021 · 548 citations
- From Toxic to Trustworthy: Using Self-Distillation and Semi-supervised Methods to Refine Neural NetworksXianda Zhang, Baolin Zheng, Jianbao Hu, Chengyang Li et al.AAAI 2024 · 3 citations
- Beating Backdoor Attack at Its Own GameMin Liu, Alberto L. Sangiovanni-Vincentelli, Xiangyu YueICCV 2023 · 19 citations
- Towards Stable Backdoor Purification through Feature Shift TuningRui Min, Zeyu Qin, Li Shen, Minhao ChengNeurIPS 2023 · 43 citations
- ATTEQ-NN: Attention-based QoE-aware Evasive Backdoor AttacksXueluan Gong, Yanjiao Chen, Jianshuo Dong, Qian WangNDSS 2022
