SSDA: Secure Source-Free Domain Adaptation
Sabbir Ahmed, Abdullah Al Arafat, Mamshad Nayeem Rizve, Rahim Hossain, Zhishan Guo, Adnan Siraj Rakin
摘要
Source-free domain adaptation (SFDA) is a popular unsupervised domain adaptation method where a pre-trained model from a source domain is adapted to a target domain without accessing any source data. Despite rich results in this area, existing literature overlooks the security challenges of the unsupervised SFDA setting in presence of a malicious source domain owner. This work investigates the effect of a source adversary which may inject a hidden malicious behavior (Backdoor/Trojan) during source training and potentially transfer it to the target domain even after benign training by the victim (target domain owner). Our investigation of the current SFDA setting reveals that because of the unique challenges present in SFDA (e.g., no source data, target label), defending against backdoor attack using existing defenses become practically ineffective in protecting the target model. To address this, we propose a novel target domain protection scheme called secure source-free domain adaptation (SSDA). SSDA adopts a single-shot model compression of a pre-trained source model and a novel knowledge transfer scheme with a spectral-norm-based loss penalty for target training. The proposed static compression and the dynamic training loss penalty are designed to suppress the malicious channels responsive to the backdoor during the adaptation stage. At the same time, the knowledge transfer from an uncompressed auxiliary model helps to recover the benign test accuracy. Our extensive evaluation on multiple dataset and domain tasks against recent backdoor attacks reveal that the proposed SSDA can successfully defend against strong backdoor attacks with little to no degradation in test accuracy compared to the vulnerable baseline SFDA methods. Our code is available at https://github.com/ML-Security- Research-LAB/SSDA.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Fisher Information guided Purification against Backdoor AttacksNazmul Karim, Abdullah Al Arafat, Adnan Siraj Rakin, Zhishan Guo 等CCS 2024 · 被引用 4 次
- Protecting Model Adaptation from Trojans in the Unlabeled DataLijun Sheng, Jian Liang, Ran He, Zilei Wang 等AAAI 2025
- Deep-TROJ: An Inference Stage Trojan Insertion Algorithm Through Efficient Weight Replacement AttackSabbir Ahmed, Ranyang Zhou, Shaahin Angizi, Adnan Siraj RakinCVPR 2024
它引用的顶会 Paper18
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li 等S&P 2019 · 被引用 1,801 次
- Do We Really Need to Access the Source Data? Source Hypothesis Transfer for Unsupervised Domain AdaptationJian Liang, Dapeng Hu, Jiashi FengICML 2020 · 被引用 1,624 次
- Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural NetworksYige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu 等ICLR 2021 · 被引用 548 次
- Exploiting the Intrinsic Neighborhood Structure for Source-free Domain AdaptationShiqi Yang, Yaxing Wang, Joost van de Weijer, Luis Herranz 等NeurIPS 2021 · 被引用 371 次
- Generalized Source-free Domain AdaptationShiqi Yang, Yaxing Wang, Joost van de Weijer, Luis Herranz 等ICCV 2021 · 被引用 319 次
相关 Paper
- Source-Free Domain Adaptation for Semantic SegmentationYuang Liu, Wei Zhang, Jun WangCVPR 2021
- Adaptive Adversarial Network for Source-free Domain AdaptationHaifeng Xia, Handong Zhao, Zhengming DingICCV 2021 · 被引用 243 次
- Revisiting Source-Free Domain Adaptation: a New Perspective via Uncertainty ControlGezheng Xu, Hui Guo, Li Yi, Charles Ling 等ICLR 2025
- Revisiting Data-Free Knowledge Distillation with Poisoned TeachersJunyuan Hong, Yi Zeng, Shuyang Yu, Lingjuan Lyu 等ICML 2023 · 被引用 16 次
- Source-Free Active Domain Adaptation via Energy-Based Locality Preserving TransferXinyao Li, Zhekai Du, Jingjing Li, Lei Zhu 等ACM MM 2022 · 被引用 24 次
