Pith. sign in

REVIEW

Rethinking Backdoor Attacks on Dataset Distillation: A Kernel Method Perspective

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2311.16646 v2 pith:HAEBYLXJ submitted 2023-11-28 cs.LG cs.CR

classification cs.LGcs.CR
keywords backdoordatasetdistillationattacksmethodstriggerkernelresilient
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Dataset distillation offers a potential means to enhance data efficiency in deep learning. Recent studies have shown its ability to counteract backdoor risks present in original training samples. In this study, we delve into the theoretical aspects of backdoor attacks and dataset distillation based on kernel methods. We introduce two new theory-driven trigger pattern generation methods specialized for dataset distillation. Following a comprehensive set of analyses and experiments, we show that our optimization-based trigger design framework informs effective backdoor attacks on dataset distillation. Notably, datasets poisoned by our designed trigger prove resilient against conventional backdoor attack detection and mitigation methods. Our empirical results validate that the triggers developed using our approaches are proficient at executing resilient backdoor attacks.

Discussion (0). Sign in to comment.

Pith tools