Skip to content
InfoResearchPeer-reviewed

Strong evasive backdoor attacks and an ensemble defense

Published
Record updated
View JSON

Summary

Researchers present an ensemble defense that combines several backdoor detectors for deep neural network classifiers, so detection does not depend on a single backdoor mechanism. The ensemble also performs backdoor inversion, which indicates the nature of a detected attack. The paper also employs mixed clean/dirty-label backdoor poisoning, an X-to-X attack the authors describe as more surgical, evasive, and harder to detect than traditional dirty-label attacks.