SSDA: Secure Source-Free Domain Adaptation
Sabbir Ahmed, Abdullah Al Arafat, Mamshad Nayeem Rizve, Rahim Hossain, Zhishan Guo, Adnan Siraj Rakin
Abstract
Source-free domain adaptation (SFDA) is a popular unsupervised domain adaptation method where a pre-trained model from a source domain is adapted to a target domain without accessing any source data. Despite rich results in this area, existing literature overlooks the security challenges of the unsupervised SFDA setting in presence of a malicious source domain owner. This work investigates the effect of a source adversary which may inject a hidden malicious behavior (Backdoor/Trojan) during source training and potentially transfer it to the target domain even after benign training by the victim (target domain owner). Our investigation of the current SFDA setting reveals that because of the unique challenges present in SFDA (e.g., no source data, target label), defending against backdoor attack using existing defenses become practically ineffective in protecting the target model. To address this, we propose a novel target domain protection scheme called secure source-free domain adaptation (SSDA). SSDA adopts a single-shot model compression of a pre-trained source model and a novel knowledge transfer scheme with a spectral-norm-based loss penalty for target training. The proposed static compression and the dynamic training loss penalty are designed to suppress the malicious channels responsive to the backdoor during the adaptation stage. At the same time, the knowledge transfer from an uncompressed auxiliary model helps to recover the benign test accuracy. Our extensive evaluation on multiple dataset and domain tasks against recent backdoor attacks reveal that the proposed SSDA can successfully defend against strong backdoor attacks with little to no degradation in test accuracy compared to the vulnerable baseline SFDA methods. Our code is available at https://github.com/ML-Security- Research-LAB/SSDA.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Fisher Information guided Purification against Backdoor AttacksNazmul Karim, Abdullah Al Arafat, Adnan Siraj Rakin, Zhishan Guo et al.CCS 2024 · 4 citations
- Protecting Model Adaptation from Trojans in the Unlabeled DataLijun Sheng, Jian Liang, Ran He, Zilei Wang et al.AAAI 2025
- Deep-TROJ: An Inference Stage Trojan Insertion Algorithm Through Efficient Weight Replacement AttackSabbir Ahmed, Ranyang Zhou, Shaahin Angizi, Adnan Siraj RakinCVPR 2024
Builds on18
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li et al.S&P 2019 · 1,801 citations
- Do We Really Need to Access the Source Data? Source Hypothesis Transfer for Unsupervised Domain AdaptationJian Liang, Dapeng Hu, Jiashi FengICML 2020 · 1,624 citations
- Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural NetworksYige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu et al.ICLR 2021 · 548 citations
- Exploiting the Intrinsic Neighborhood Structure for Source-free Domain AdaptationShiqi Yang, Yaxing Wang, Joost van de Weijer, Luis Herranz et al.NeurIPS 2021 · 371 citations
- Generalized Source-free Domain AdaptationShiqi Yang, Yaxing Wang, Joost van de Weijer, Luis Herranz et al.ICCV 2021 · 319 citations
Related papers
- Source-Free Domain Adaptation for Semantic SegmentationYuang Liu, Wei Zhang, Jun WangCVPR 2021
- Adaptive Adversarial Network for Source-free Domain AdaptationHaifeng Xia, Handong Zhao, Zhengming DingICCV 2021 · 243 citations
- Revisiting Source-Free Domain Adaptation: a New Perspective via Uncertainty ControlGezheng Xu, Hui Guo, Li Yi, Charles Ling et al.ICLR 2025
- Revisiting Data-Free Knowledge Distillation with Poisoned TeachersJunyuan Hong, Yi Zeng, Shuyang Yu, Lingjuan Lyu et al.ICML 2023 · 16 citations
- Source-Free Active Domain Adaptation via Energy-Based Locality Preserving TransferXinyao Li, Zhekai Du, Jingjing Li, Lei Zhu et al.ACM MM 2022 · 24 citations
