Image Shortcut Squeezing: Countering Perturbative Availability Poisons with Compression
Zhuoran Liu, Zhengyu Zhao, Martha A. Larson
Abstract
Perturbative availability poisons (PAPs) add small changes to images to prevent their use for model training. Current research adopts the belief that practical and effective approaches to countering PAPs do not exist. In this paper, we argue that it is time to abandon this belief. We present extensive experiments showing that 12 state-of-the-art PAP methods are vulnerable to Image Shortcut Squeezing (ISS), which is based on simple compression. For example, on average, ISS restores the CIFAR-10 model accuracy to 81.73%, surpassing the previous best preprocessing-based countermeasures by 37.97% absolute. ISS also (slightly) outperforms adversarial training and has higher generalizability to unseen perturbation norms and also higher efficiency. Our investigation reveals that the property of PAP perturbations depends on the type of surrogate model used for poison generation, and it explains why a specific ISS compression yields the best performance for a specific type of PAP perturbation. We further test stronger, adaptive poisoning, and show it falls short of being an ideal defense against ISS. Overall, our results demonstrate the importance of considering various (simple) countermeasures to ensure the meaningfulness of analysis carried out during the development of PAP methods. Our code is available at https://github.com/ liuzrcc/ImageShortcutSqueezing .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers21
- Purify Unlearnable Examples via Rate-Constrained Variational AutoencodersYi Yu, Yufei Wang, Song Xia, Wenhan Yang et al.ICML 2024 · 22 citations
- UnSeg: One Universal Unlearnable Example Generator is Enough against All Image SegmentationYe Sun, Hao Zhang, Tiehua Zhang, Xingjun Ma et al.NeurIPS 2024 · 18 citations
- Unlearnable Examples Give a False Sense of Security: Piercing through Unexploitable Data with Learnable ExamplesWan Jiang, Yunfeng Diao, He Wang, Jianxin Sun et al.ACM MM 2023 · 14 citations
- Efficient Availability Attacks against Supervised and Contrastive Learning SimultaneouslyYihan Wang, Yifan Zhu, Xiao-Shan GaoNeurIPS 2024 · 14 citations
- Detecting and Corrupting Convolution-based Unlearnable ExamplesMinghui Li, Xianlong Wang, Zhifei Yu, Shengshan Hu et al.AAAI 2025 · 13 citations
Builds on20
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- The Pitfalls of Simplicity Bias in Neural NetworksHarshay Shah, Kaustav Tamuly, Aditi Raghunathan, Prateek Jain et al.NeurIPS 2020 · 503 citations
Related papers
- Availability Attacks Create ShortcutsDa Yu, Huishuai Zhang, Wei Chen, Jian Yin et al.KDD 2022 · 28 citations
- NAPPure: Adversarial Purification for Robust Image Classification Under Non-Additive PerturbationsJunjie Nan, Jianing Li, Wei Chen, Mingkun Zhang et al.ICCV 2025
- Unrestricted Adversarial Examples via Semantic ManipulationAnand Bhattad, Min Jin Chong, Kaizhao Liang, Bo Li et al.ICLR 2020 · 177 citations
- Sample Efficient Detection and Classification of Adversarial Attacks via Self-Supervised EmbeddingsMazda Moayeri, Soheil FeiziICCV 2021 · 20 citations
- One Man's Trash Is Another Man's Treasure: Resisting Adversarial Examples by Adversarial ExamplesChang Xiao, Changxi ZhengCVPR 2020
