PECAN: A Deterministic Certified Defense Against Backdoor Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Yuhao, Albarghouthi, Aws, D'Antoni, Loris
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929348900028416
author Zhang, Yuhao
Albarghouthi, Aws
D'Antoni, Loris
author_facet Zhang, Yuhao
Albarghouthi, Aws
D'Antoni, Loris
contents Neural networks are vulnerable to backdoor poisoning attacks, where the attackers maliciously poison the training set and insert triggers into the test input to change the prediction of the victim model. Existing defenses for backdoor attacks either provide no formal guarantees or come with expensive-to-compute and ineffective probabilistic guarantees. We present PECAN, an efficient and certified approach for defending against backdoor attacks. The key insight powering PECAN is to apply off-the-shelf test-time evasion certification techniques on a set of neural networks trained on disjoint partitions of the data. We evaluate PECAN on image classification and malware detection datasets. Our results demonstrate that PECAN can (1) significantly outperform the state-of-the-art certified backdoor defense, both in defense strength and efficiency, and (2) on real back-door attacks, PECAN can reduce attack success rate by order of magnitude when compared to a range of baselines from the literature.
format Preprint
id arxiv_https___arxiv_org_abs_2301_11824
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle PECAN: A Deterministic Certified Defense Against Backdoor Attacks
Zhang, Yuhao
Albarghouthi, Aws
D'Antoni, Loris
Cryptography and Security
Machine Learning
Neural networks are vulnerable to backdoor poisoning attacks, where the attackers maliciously poison the training set and insert triggers into the test input to change the prediction of the victim model. Existing defenses for backdoor attacks either provide no formal guarantees or come with expensive-to-compute and ineffective probabilistic guarantees. We present PECAN, an efficient and certified approach for defending against backdoor attacks. The key insight powering PECAN is to apply off-the-shelf test-time evasion certification techniques on a set of neural networks trained on disjoint partitions of the data. We evaluate PECAN on image classification and malware detection datasets. Our results demonstrate that PECAN can (1) significantly outperform the state-of-the-art certified backdoor defense, both in defense strength and efficiency, and (2) on real back-door attacks, PECAN can reduce attack success rate by order of magnitude when compared to a range of baselines from the literature.
title PECAN: A Deterministic Certified Defense Against Backdoor Attacks
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2301.11824