Strong Data Augmentation Sanitizes Poisoning and Backdoor Attacks Without an Accuracy Tradeoff
Data poisoning and backdoor attacks manipulate victim models by maliciously\nmodifying training data. In light of this growing threat, a recent survey of\nindustry professionals revealed heightened fear in the private sector regarding\ndata poisoning. Many previous defenses against poisoning either fail in the\nface of increasingly strong attacks, or they significantly degrade performance.\nHowever, we find that strong data augmentations, such as mixup and CutMix, can\nsignificantly diminish the threat of poisoning and backdoor attacks without\ntrading off performance. We further verify the effectiveness of this simple\ndefense against adaptive poisoning methods, and we compare to baselines\nincluding the popular differentially private SGD (DP-SGD) defense. In the\ncontext of backdoors, CutMix greatly mitigates the attack while simultaneously\nincreasing validation accuracy by 9%.\n
Paper
References (24)
Scroll for more · 12 remaining