Elijah: Eliminating Backdoors Injected in Diffusion Models via Distribution Shift

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: An, Shengwei, Chou, Sheng-Yen, Zhang, Kaiyuan, Xu, Qiuling, Tao, Guanhong, Shen, Guangyu, Cheng, Siyuan, Ma, Shiqing, Chen, Pin-Yu, Ho, Tsung-Yi, Zhang, Xiangyu
Format: Preprint
Veröffentlicht: 2023
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866910318342438912
author An, Shengwei
Chou, Sheng-Yen
Zhang, Kaiyuan
Xu, Qiuling
Tao, Guanhong
Shen, Guangyu
Cheng, Siyuan
Ma, Shiqing
Chen, Pin-Yu
Ho, Tsung-Yi
Zhang, Xiangyu
author_facet An, Shengwei
Chou, Sheng-Yen
Zhang, Kaiyuan
Xu, Qiuling
Tao, Guanhong
Shen, Guangyu
Cheng, Siyuan
Ma, Shiqing
Chen, Pin-Yu
Ho, Tsung-Yi
Zhang, Xiangyu
contents Diffusion models (DM) have become state-of-the-art generative models because of their capability to generate high-quality images from noises without adversarial training. However, they are vulnerable to backdoor attacks as reported by recent studies. When a data input (e.g., some Gaussian noise) is stamped with a trigger (e.g., a white patch), the backdoored model always generates the target image (e.g., an improper photo). However, effective defense strategies to mitigate backdoors from DMs are underexplored. To bridge this gap, we propose the first backdoor detection and removal framework for DMs. We evaluate our framework Elijah on hundreds of DMs of 3 types including DDPM, NCSN and LDM, with 13 samplers against 3 existing backdoor attacks. Extensive experiments show that our approach can have close to 100% detection accuracy and reduce the backdoor effects to close to zero without significantly sacrificing the model utility.
format Preprint
id arxiv_https___arxiv_org_abs_2312_00050
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Elijah: Eliminating Backdoors Injected in Diffusion Models via Distribution Shift
An, Shengwei
Chou, Sheng-Yen
Zhang, Kaiyuan
Xu, Qiuling
Tao, Guanhong
Shen, Guangyu
Cheng, Siyuan
Ma, Shiqing
Chen, Pin-Yu
Ho, Tsung-Yi
Zhang, Xiangyu
Cryptography and Security
Artificial Intelligence
Machine Learning
Diffusion models (DM) have become state-of-the-art generative models because of their capability to generate high-quality images from noises without adversarial training. However, they are vulnerable to backdoor attacks as reported by recent studies. When a data input (e.g., some Gaussian noise) is stamped with a trigger (e.g., a white patch), the backdoored model always generates the target image (e.g., an improper photo). However, effective defense strategies to mitigate backdoors from DMs are underexplored. To bridge this gap, we propose the first backdoor detection and removal framework for DMs. We evaluate our framework Elijah on hundreds of DMs of 3 types including DDPM, NCSN and LDM, with 13 samplers against 3 existing backdoor attacks. Extensive experiments show that our approach can have close to 100% detection accuracy and reduce the backdoor effects to close to zero without significantly sacrificing the model utility.
title Elijah: Eliminating Backdoors Injected in Diffusion Models via Distribution Shift
topic Cryptography and Security
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2312.00050