{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/adversarial-neuron-pruning-purifies","title":"Adversarial Neuron Pruning Purifies Backdoored Deep Models","arxiv_id":"2110.14430","date":"2021-10-27","proceeding":"NeurIPS 2021 12","authors":["Dongxian Wu","Yisen Wang"],"abstract":"As deep neural networks (DNNs) are growing larger, their requirements for computational resources become huge, which makes outsourcing training more popular. Training in a third-party platform, however, may introduce potential risks that a malicious trainer will return backdoored DNNs, which behave normally on clean samples but output targeted misclassifications whenever a trigger appears at the test time. Without any knowledge of the trigger, it is difficult to distinguish or recover benign DNNs from backdoored ones. In this paper, we first identify an unexpected sensitivity of backdoored DNNs, that is, they are much easier to collapse and tend to predict the target label on clean samples when their neurons are adversarially perturbed. Based on these observations, we propose a novel model repairing method, termed Adversarial Neuron Pruning (ANP), which prunes some sensitive neurons to purify the injected backdoor. Experiments show, even with only an extremely small amount of clean data (e.g., 1%), ANP effectively removes the injected backdoor without causing obvious performance degradation.","url_abs":"https://arxiv.org/abs/2110.14430v1","url_pdf":"https://arxiv.org/pdf/2110.14430v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"adversarial-neuron-pruning-purifies","repo_url":"https://github.com/csdongxian/anp_backdoor","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":null},{"paper_slug":"adversarial-neuron-pruning-purifies","repo_url":"https://github.com/csdongxian/csdongxian","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"none","reach":{"status":"ok"}}],"tasks":[],"methods":[{"method_slug":"pruning","method_name":"Pruning"},{"method_slug":"test","method_name":"Test"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2110.14430","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2110.14430"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"deterministic:regex_extraction","url":"https://github.com/csdongxian/ANP_backdoor","reach":null},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/csdongxian/anp_backdoor","reach":null},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/csdongxian/csdongxian","reach":{"status":"ok"}}],"summary":{"ran_honours":2,"unverified":1},"by_repo_kind":{"official":{"samples":3,"ran":2,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":3,"samples":[{"code_sha256_prefix":"f634daea78f08e78","entry":"test","repo":"csdongxian/ANP_backdoor","repo_kind":"official","path":"train_backdoor_cifar.py","file_url":"https://github.com/csdongxian/ANP_backdoor/blob/HEAD/train_backdoor_cifar.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":"well_formed","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"f634daea78f08e78"}},{"code_sha256_prefix":"1042d89ceda24cdb","entry":"train","repo":"csdongxian/ANP_backdoor","repo_kind":"official","path":"train_backdoor_cifar.py","file_url":"https://github.com/csdongxian/ANP_backdoor/blob/HEAD/train_backdoor_cifar.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":"well_formed","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"1042d89ceda24cdb"}},{"code_sha256_prefix":"e0172f12ef9cd5cb","entry":"NoisyBatchNorm2d","repo":"csdongxian/anp_backdoor","repo_kind":"official","path":"models/anp_batchnorm.py","file_url":"https://github.com/csdongxian/anp_backdoor/blob/HEAD/models/anp_batchnorm.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"e0172f12ef9cd5cb"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}