Journal of Applied Sciences ›› 2023, Vol. 41 ›› Issue (2): 218-227.doi: 10.3969/j.issn.0255-8297.2023.02.003

• Digital Media Forensics and Security • Previous Articles     Next Articles

Segmented Backdoor Defense Based on Local Gradient and Global Gradient Ascent

XIAO Xiaotong, DING Jianwei, ZHANG Qi   

  1. College of Information and Cyber Security, People's Public Security University of China, Beijing 100038, China
  • Received:2022-10-28 Online:2023-03-31 Published:2023-03-29

Abstract: Backdoor triggers tend to be hidden and are difficult to detect. To solve this problem, a segmented backdoor defense (SBD) method based on local and global gradient ascent is proposed. In the early stage of training, local gradient ascent is introduced to enlarge the difference between the average training loss of backdoor samples and clean samples. A small number of high-precision backdoor samples are isolated to facilitate backdoor forgetting in the later stage. In the backdoor forgetting stage, global gradient ascent is introduced to reduce the correlation between backdoor samples and target categories to achieve defense. Based on three benchmark datasets GTSRB, Cifar10 and MNIST, a large number of experiments are conducted on the WideResNet-16-1 model against six advanced backdoor attacks. It is shown that the proposed segmented backdoor defense method can reduce the success rate of most attacks to below 5%. Moreover, the proposed method can train a clean equivalent learning model on both backdoor dataset and clean dataset.

Key words: backdoor defense, backdoor detection, deep learning, backdoor attack, information security

CLC Number: