Built independently by an author, for readers. Read the story and support ChapterPal

keyword

perturbative availability poisons

Perturbative availability poisons are subtle, imperceptible modifications added to training data to prevent machine learning models from learning generalizable patterns, effectively rendering the dataset unlearnable. By introducing crafted noise or shortcut features into samples without altering their true labels or human-perceptible content, these perturbations cause learning algorithms to rely on artificial signals rather than meaningful semantic information. As a result, models trained on the poisoned data experience severe performance degradation and fail to generalize when evaluated on clean, unaltered test data. Unlike backdoor attacks that seek to insert targeted vulnerabilities or triggers, perturbative availability poisons aim to deny the overall utility of datasets for model training, commonly functioning as a protective countermeasure to safeguard private data and intellectual property against unauthorized machine learning exploitation.

1 item

Image Shortcut Squeezing: Countering Perturbative Availability Poisons with Compression

Image Shortcut Squeezing: Countering Perturbative Availability Poisons with Compression

Zhuoran Liu, Zhengyu Zhao, Martha A. Larson

OrganizationsCISPA Helmholtz Center for Information SecurityRadboud UniversityXi'an Jiaotong University

Why you should read this

Proposes Image Shortcut Squeezing, a simple compression-based defense that neutralizes twelve state-of-the-art perturbative availability poisons by exploiting the frequency characteristics of poison shortcuts, matching or outperforming adversarial training with far greater efficiency.

Perturbative availability poisons (PAPs) add small changes to images to prevent their use for model training. Current research adopts the belief that practical and effective approaches to countering PAPs do not exist. In this paper, we argue that it is time to abandon this belief. We present extensive experiments showing that 12 state-of-the-art PAP methods are vulnerable to Image Shortcut Squeezing (ISS), which is based on simple compression. For example, on average, ISS restores the CIFAR-10 model accuracy to 81.73%, surpassing the previous best preprocessing-based countermeasures by 37.97% absolute. ISS also (slightly) outperforms adversarial training and has higher generalizability to unseen perturbation norms and also higher efficiency. Our investigation reveals that the property of PAP perturbations depends on the type of surrogate model used for poison generation, and it explains why a specific ISS compression yields the best performance for a specific type of PAP perturbation. We further test stronger, adaptive poisoning, and show it falls short of being an ideal defense against ISS. Overall, our results demonstrate the importance of considering various (simple) countermeasures to ensure the meaningfulness of analysis carried out during the development of PAP methods. Our code is available at https://github.com/liuzrcc/ImageShortcutSqueezing.

Added

2026-10-03