Image Shortcut Squeezing: Countering Perturbative Availability Poisons with Compression
Zhuoran LiuZhengyu ZhaoMartha A. Larson
Proposes Image Shortcut Squeezing, a simple compression-based defense that neutralizes twelve state-of-the-art perturbative availability poisons by exploiting the frequency characteristics of poison shortcuts, matching or outperforming adversarial training with far greater efficiency.
Online image protection increasingly relies on perturbative availability poisons, which introduce imperceptible modifications to training images to prevent unauthorized machine learning models from learning useful representations. Prior literature has maintained that these data-protecting poisons are virtually impossible to neutralize without either suffering major computational overhead or incurring large penalties on model accuracy. The article challenges this widely held belief by evaluating whether simple image compression can effectively neutralize these training-time availability poisons.
To test this, the article analyzes 12 leading poisoning techniques and categorizes them by how their perturbations are generated: using slightly-trained surrogate models, fully-trained surrogate models, or surrogate-free methods. The evaluation spans multiple standard benchmarks (CIFAR-10, CIFAR-100, and a 100-class ImageNet subset) across various neural network architectures, comparing compression defenses against standard data augmentations, image filters, and robust adversarial training.
The findings show that poison patterns correlate directly with their generation method: slightly-trained models generate low-frequency color perturbations, while fully-trained models generate high-frequency patterns. Exploiting this insight, the article introduces Image Shortcut Squeezing, a defense applying simple grayscale and JPEG compression to remove these shortcut patterns during training. On CIFAR-10, this approach restores average classification accuracy to 81.73%, outperforming previous preprocessing countermeasures by an absolute margin of 37.97%. The method achieves performance comparable to adversarial training while requiring only one-seventh of the training time and generalizing across multiple perturbation bounds, including challenging one-pixel modifications where adversarial training fails completely.
These results indicate that current data-poisoning defenses for privacy and proprietary protection provide a false sense of security against model exploiters, as they can be dismantled with basic, computationally inexpensive preprocessing. In addition, tests with adaptive poisons indicate that even attack-aware modifications currently struggle to circumvent these compression defenses effectively.
For practitioners training machine learning models on potentially poisoned external data, combining grayscale and JPEG compression offers an efficient, immediate countermeasure that restores model utility with minimal accuracy loss on clean data. Researchers developing future data protection methods must incorporate compression countermeasures during benchmark evaluations. However, stakeholders should recognize that data protection is an evolving dynamic; future adaptive poisons may eventually bypass static compression rules, warranting ongoing research into automated attack identification and accuracy-preserving transformations.
- Paper: Transferable Unlearnable Examples, Jie Ren et al. (2023). Its unlearnable-example framework establishes the availability-poisoning threat that the source tests defenses against.
- Paper: Countering Adversarial Images using Input Transformations, Chuan Guo et al. (2018). Its study of JPEG and other input transformations against imperceptible perturbations provides the defense precedent the source adapts to training-time poisons.
- Paper: Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks, Weilin Xu et al. (2017). Its feature-squeezing approach shows how simple input reductions can blunt perturbation-based attacks, preparing readers for the source’s compression-based defense.
No sufficiently relevant recommendations were found.
