Built independently by an author, for readers. Read the story and support ChapterPal

keyword

input-space attacks

Input-space attacks are adversarial techniques in machine learning where an attacker modifies raw input data directly to manipulate a model into making incorrect predictions or activating hidden behaviors such as backdoors. Unlike feature-space or latent-space attacks that manipulate the internal representations learned within intermediate layers of a neural network, input-space attacks operate exclusively on the original data domain, such as changing pixel values in an image, characters in text, or samples in an audio signal, before any model processing occurs. These modifications are typically designed under specific mathematical constraints to remain imperceptible or visually realistic to human observers while still exploiting the model decision boundaries. Operating directly at the data ingestion stage makes input-space attacks highly realistic threat vectors against deployed artificial intelligence systems, as they can be delivered through standard user interfaces without requiring internal access to model architecture or hidden embeddings.

1 item

Reconstructive Neuron Pruning for Backdoor Defense

Reconstructive Neuron Pruning for Backdoor Defense

Yige Li, Xixiang Lyu, Xingjun Ma, Nodens Koren, Lingjuan Lyu, Bo Li, Yu-Gang Jiang

OrganizationsFudan UniversityShanghai Artificial Intelligence LaboratorySony CorporationUniversity of CopenhagenUniversity of Illinois Urbana-ChampaignXidian University

Why you should read this

Proposes an asymmetric unlearning and filter-recovery framework that exposes and prunes backdoor neurons using only a small set of clean data, effectively purifying backdoored models across diverse attacks without sacrificing clean classification accuracy.

Deep neural networks (DNNs) have been found to be vulnerable to backdoor attacks, raising security concerns about their deployment in mission-critical applications. While existing defense methods have demonstrated promising results, it is still not clear how to effectively remove backdoor-associated neurons in backdoored DNNs. In this paper, we propose a novel defense called Reconstructive Neuron Pruning (RNP) to expose and prune backdoor neurons via an unlearning and then recovering process. Specifically, RNP first unlearns the neurons by maximizing the model’s error on a small subset of clean samples and then recovers the neurons by minimizing the model’s error on the same data. In RNP, unlearning is operated at the neuron level while recovering is operated at the filter level, forming an asymmetric reconstructive learning procedure. We show that such an asymmetric process on only a few clean samples can effectively expose and prune the backdoor neurons implanted by a wide range of attacks, achieving a new state-of-the-art defense performance. Moreover, the unlearned model at the intermediate step of our RNP can be directly used to improve other backdoor defense tasks including backdoor removal, trigger recovery, backdoor label detection, and backdoor sample detection. Code is available at https://github.com/bboylyg/RNP.

Added

2026-09-26