Built independently by an author, for readers. Read the story and support ChapterPal

keyword

Image Shortcut Squeezing

Image Shortcut Squeezing is a machine learning data preprocessing defense that applies image compression techniques to neutralize perturbative availability poisons in training data. Perturbative availability poisons introduce subtle, imperceptible alterations to images that act as artificial shortcuts, which trick neural networks into memorizing noise rather than learning genuine, generalizable visual features. By compressing training images before model optimization, Image Shortcut Squeezing removes or disrupts these fragile shortcut perturbations, effectively restoring the training utility of protected or poisoned datasets with minimal computational overhead compared to retraining-based defenses such as adversarial training.

1 item

Image Shortcut Squeezing: Countering Perturbative Availability Poisons with Compression

Image Shortcut Squeezing: Countering Perturbative Availability Poisons with Compression

Zhuoran Liu, Zhengyu Zhao, Martha A. Larson

OrganizationsCISPA Helmholtz Center for Information SecurityRadboud UniversityXi'an Jiaotong University

Why you should read this

Proposes Image Shortcut Squeezing, a simple compression-based defense that neutralizes twelve state-of-the-art perturbative availability poisons by exploiting the frequency characteristics of poison shortcuts, matching or outperforming adversarial training with far greater efficiency.

Perturbative availability poisons (PAPs) add small changes to images to prevent their use for model training. Current research adopts the belief that practical and effective approaches to countering PAPs do not exist. In this paper, we argue that it is time to abandon this belief. We present extensive experiments showing that 12 state-of-the-art PAP methods are vulnerable to Image Shortcut Squeezing (ISS), which is based on simple compression. For example, on average, ISS restores the CIFAR-10 model accuracy to 81.73%, surpassing the previous best preprocessing-based countermeasures by 37.97% absolute. ISS also (slightly) outperforms adversarial training and has higher generalizability to unseen perturbation norms and also higher efficiency. Our investigation reveals that the property of PAP perturbations depends on the type of surrogate model used for poison generation, and it explains why a specific ISS compression yields the best performance for a specific type of PAP perturbation. We further test stronger, adaptive poisoning, and show it falls short of being an ideal defense against ISS. Overall, our results demonstrate the importance of considering various (simple) countermeasures to ensure the meaningfulness of analysis carried out during the development of PAP methods. Our code is available at https://github.com/liuzrcc/ImageShortcutSqueezing.

Added

2026-10-03