PureGen: Universal Data Purification for Train-Time Poison Defense via Generative Model Dynamics
Bhat, Sunay, Jiang, Jeffrey, Pooladzandi, Omead, Branch, Alexander, Pottie, Gregory
–arXiv.org Artificial Intelligence
Train-time data poisoning attacks threaten machine learning models by introducing adversarial examples during training, leading to misclassification. Current defense methods often reduce generalization performance, are attack-specific, and impose significant training overhead. To address this, we introduce a set of universal data purification methods using a stochastic transform, Ψ(x), realized via iterative Langevin dynamics of Energy-Based Models (EBMs), Denoising Diffusion Probabilistic Models (DDPMs), or both. These approaches purify poisoned data with minimal impact on classifier generalization. Our specially trained EBMs and DDPMs provide state-of-the-art defense against various attacks (including Narcissus, Bullseye Polytope, Gradient Matching) on CIFAR-10, Tiny-ImageNet, and CINIC-10, without needing attack or classifier-specific information. We discuss performance trade-offs and show that our methods remain highly effective even with poisoned or distributionally shifted generative model training data. We make our code available on GitHub.
arXiv.org Artificial Intelligence
Jun-2-2024
- Country:
- North America
- United States > California
- Los Angeles County > Los Angeles (0.28)
- Canada > Ontario
- Toronto (0.04)
- United States > California
- North America
- Genre:
- Research Report (0.82)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Energy (0.67)
- Technology: