Pith. sign in

REVIEW 1 cited by

Certified Robustness to Clean-Label Poisoning Using Diffusion Denoising

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2403.11981 v2 pith:5F7ANLJH submitted 2024-03-18 cs.CR cs.CVcs.LG

classification cs.CRcs.CVcs.LG
keywords attacksclean-labeldefensepoisoningcertifiedadversarialattackdata
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

We present a certified defense to clean-label poisoning attacks under $\ell_2$-norm. These attacks work by injecting a small number of poisoning samples (e.g., 1%) that contain bounded adversarial perturbations into the training data to induce a targeted misclassification of a test-time input. Inspired by the adversarial robustness achieved by $randomized$ $smoothing$, we show how an off-the-shelf diffusion denoising model can sanitize the tampered training data. We extensively test our defense against seven clean-label poisoning attacks in both $\ell_2$ and $\ell_{\infty}$-norms and reduce their attack success to 0-16% with only a negligible drop in the test accuracy. We compare our defense with existing countermeasures against clean-label poisoning, showing that the defense reduces the attack success the most and offers the best model utility. Our results highlight the need for future work on developing stronger clean-label attacks and using our certified yet practical defense as a strong baseline to evaluate these attacks.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. CopyrightShield: Enhancing Diffusion Model Security against Copyright Infringement Attacks

    cs.AI 2024-12 reject novelty 5.0 of 10

    A defense framework that uses masked image similarity and data attribution to detect and mitigate copyright-infringing backdoor samples in diffusion models.

Pith tools