Lune

NDSS2025顶会

Try to Poison My Deep Learning Data? Nowhere to Hide Your Trajectory Spectrum!

Yansong Gao, Huaibing Peng, Hua Ma, Zhi Zhang, Shuo Wang, Rayne Holland, Anmin Fu, Minhui Xue, Derek Abbott

出版方
2025年份

摘要

—In the Data as a Service (DaaS) model, data cura-tors, such as commercial providers like Amazon Mechanical Turk, Appen, and TELUS International, aggregate quality data from numerous contributors and monetize it for deep learning (DL) model providers. However, malicious contributors can poison this data, embedding backdoors in the trained DL models. Existing methods for detecting poisoned samples face significant limitations: they often rely on reserved clean data; they are sensitive to the poisoning rate, trigger type, and backdoor type; and they are specific to classification tasks. These limitations hinder their practical adoption by data curators. This work, for the first time, investigates the training trajectory of poisoned samples in the spectrum domain , revealing distinctions from benign samples that are not apparent in the original non-spectrum domain. Building on this novel perspective, we propose Telltale to detect and sanitize poisoned samples as a one-time effort, addressing all of the aforementioned limitations of prior work. Through extensive experiments, Telltale demonstrates the ability to defeat both universal and challenging partial backdoor types without relying on any reserved clean data. Telltale is also validated to be agnostic to various trigger types, including the advanced clean-label trigger attack, Narcissus (CCS’2023). Moreover, Telltale proves effective across diverse data modalities (e.g., image, audio and text) and non-classification tasks (e.g., regression)—making it the only known training phase poisoned sample detection method applicable to non-classification tasks. In all our evaluations, Telltale achieves a detection accuracy (i.e., accurately identifying poisoned samples) of at least 95.52% and a false positive rate (i.e., falsely recognizing benign samples as poisoned ones) no higher than 0.61%. Comparisons with state-of-the-art methods, ASSET (Usenix’2023) and CT (Usenix’2023), further affirm Telltale ’s superior performance. More specifically, ASSET fails to handle partial backdoor types and incurs an unbearable false positive rate with clean/benign datasets common in practice, while CT fails against the Narcissus trigger. In contrast, Telltale proves highly effective across testing scenarios where prior work fails. The source code is released at https://github.com/MPaloze/Telltale.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper35

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖