The Perils of Learning From Unlabeled Data: Backdoor Attacks on Semi-supervised Learning
Virat Shejwalkar, Lingjuan Lyu, Amir Houmansadr
Abstract
Semi-supervised machine learning (SSL) is gaining popularity as it reduces the cost of training ML models. It does so by using very small amounts of (expensive, well-inspected) labeled data and large amounts of (cheap, non-inspected) unlabeled data. SSL has shown comparable or even superior performances compared to conventional fully-supervised ML techniques. In this paper, we show that the key feature of SSL that it can learn from (non-inspected) unlabeled data exposes SSL to strong poisoning attacks. In fact, we argue that, due to its reliance on non-inspected unlabeled data, poisoning is a much more severe problem in SSL than in conventional fully-supervised ML. Specifically, we design a backdoor poisoning attack on SSL that can be conducted by a weak adversary with no knowledge of target SSL pipeline. This is unlike prior poisoning attacks in fully-supervised settings that assume strong adversaries with practically-unrealistic capabilities. We show that by poisoning only 0.2% of the unlabeled training data, our attack can cause misclassification of more than 80% of test inputs (when they contain the adversary's backdoor trigger). Our attacks remain effective across twenty combinations of benchmark datasets and SSL algorithms, and even circumvent the state-of-the-art defenses against backdoor attacks. Our work raises significant concerns about the practical utility of existing SSL algorithms.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ee8b944d-2da0-4db3-8234-0413e4de7837Cited by top-tier papers3
- Improving Group Robustness on Spurious Correlation Requires Preciser Group InferenceYujin Han, Difan ZouICML 2024 · 13 citations
- SABRE-FL: Selective and Accurate Backdoor Rejection for Federated Prompt LearningMomin Ahmad Khan, Yasra Chandio, Fatima M. AnwarICLR 2026 · 2 citations
- Protecting Model Adaptation from Trojans in the Unlabeled DataLijun Sheng, Jian Liang, Ran He, Zilei Wang et al.AAAI 2025
Builds on23
- A Simple Framework for Contrastive Learning of Visual RepresentationsTing Chen, Simon Kornblith, Mohammad Norouzi, Geoffrey E. HintonICML 2020 · 24,064 citations
- FixMatch: Simplifying Semi-Supervised Learning with Consistency and ConfidenceKihyuk Sohn, David Berthelot, Nicholas Carlini, Zizhao Zhang et al.NeurIPS 2020 · 5,129 citations
- RandAugment: Practical Automated Data Augmentation with a Reduced Search SpaceEkin Dogus Cubuk, Barret Zoph, Jonathon Shlens, Quoc LeNeurIPS 2020 · 4,453 citations
- Unsupervised Data Augmentation for Consistency TrainingQizhe Xie, Zihang Dai, Eduard H. Hovy, Thang Luong et al.NeurIPS 2020 · 2,774 citations
- FlexMatch: Boosting Semi-Supervised Learning with Curriculum Pseudo LabelingBowen Zhang, Yidong Wang, Wenxin Hou, Hao Wu et al.NeurIPS 2021 · 1,389 citations
Related papers
- DeHiB: Deep Hidden Backdoor Attack on Semi-supervised Learning via Adversarial PerturbationZhicong Yan, Gaolei Li, Yuan Tian, Jun Wu et al.AAAI 2021 · 43 citations
- Poisoning the Unlabeled Dataset of Semi-Supervised LearningNicholas CarliniUSENIX Security 2021 · 80 citations
- An Embarrassingly Simple Backdoor Attack on Self-supervised LearningChangjiang Li, Ren Pang, Zhaohan Xi, Tianyu Du et al.ICCV 2023 · 54 citations
- Defending Against Patch-based Backdoor Attacks on Self-Supervised LearningAjinkya Tejankar, Maziar Sanjabi, Qifan Wang, Sinong Wang et al.CVPR 2023
- Phantom: Untargeted Poisoning Attacks on Semi-Supervised LearningJonathan Knauer, Phillip Rieger, Hossein Fereidooni, Ahmad-Reza SadeghiCCS 2024
