{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/backdoor-secrets-unveiled-identifying","title":"Backdoor Secrets Unveiled: Identifying Backdoor Data with Optimized Scaled Prediction Consistency","arxiv_id":"2403.10717","date":"2024-03-15","proceeding":null,"authors":["Soumyadeep Pal","Yuguang Yao","Ren Wang","Bingquan Shen","Sijia Liu"],"abstract":"Modern machine learning (ML) systems demand substantial training data, often resorting to external sources. Nevertheless, this practice renders them vulnerable to backdoor poisoning attacks. Prior backdoor defense strategies have primarily focused on the identification of backdoored models or poisoned data characteristics, typically operating under the assumption of access to clean data. In this work, we delve into a relatively underexplored challenge: the automatic identification of backdoor data within a poisoned dataset, all under realistic conditions, i.e., without the need for additional clean data or without manually defining a threshold for backdoor detection. We draw an inspiration from the scaled prediction consistency (SPC) technique, which exploits the prediction invariance of poisoned data to an input scaling factor. Based on this, we pose the backdoor data identification problem as a hierarchical data splitting optimization problem, leveraging a novel SPC-based loss function as the primary optimization objective. Our innovation unfolds in several key aspects. First, we revisit the vanilla SPC method, unveiling its limitations in addressing the proposed backdoor identification problem. Subsequently, we develop a bi-level optimization-based approach to precisely identify backdoor data by minimizing the advanced SPC loss. Finally, we demonstrate the efficacy of our proposal against a spectrum of backdoor attacks, encompassing basic label-corrupted attacks as well as more sophisticated clean-label attacks, evaluated across various benchmark datasets. Experiment results show that our approach often surpasses the performance of current baselines in identifying backdoor data points, resulting in about 4%-36% improvement in average AUROC. Codes are available at https://github.com/OPTML-Group/BackdoorMSPC.","url_abs":"https://arxiv.org/abs/2403.10717v1","url_pdf":"https://arxiv.org/pdf/2403.10717v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"backdoor-secrets-unveiled-identifying","repo_url":"https://github.com/optml-group/backdoormspc","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"backdoor-defense","task_name":"backdoor defense"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2403.10717","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2403.10717"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/optml-group/backdoormspc","reach":null}],"summary":{"ran_draft_wrong":3,"ran_honours":1,"unverified":1},"by_repo_kind":{"official":{"samples":5,"ran":4,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":5,"samples":[{"code_sha256_prefix":"cf38377301d8f50a","entry":"create_optimizer","repo":"optml-group/backdoormspc","repo_kind":"official","path":"trainnew.py","file_url":"https://github.com/optml-group/backdoormspc/blob/HEAD/trainnew.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"cf38377301d8f50a"}},{"code_sha256_prefix":"17b9cca691520338","entry":"get_lr","repo":"optml-group/backdoormspc","repo_kind":"official","path":"trainnew.py","file_url":"https://github.com/optml-group/backdoormspc/blob/HEAD/trainnew.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":"well_formed","behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"17b9cca691520338"}},{"code_sha256_prefix":"5587a14507508ec5","entry":"l_MSPC","repo":"optml-group/backdoormspc","repo_kind":"official","path":"bilevel_losses.py","file_url":"https://github.com/optml-group/backdoormspc/blob/HEAD/bilevel_losses.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"5587a14507508ec5"}},{"code_sha256_prefix":"303154361289ff34","entry":"l_SPC","repo":"optml-group/backdoormspc","repo_kind":"official","path":"bilevel_losses.py","file_url":"https://github.com/optml-group/backdoormspc/blob/HEAD/bilevel_losses.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"303154361289ff34"}},{"code_sha256_prefix":"5a653cccf3a82189","entry":"validate","repo":"optml-group/backdoormspc","repo_kind":"official","path":"trainnew.py","file_url":"https://github.com/optml-group/backdoormspc/blob/HEAD/trainnew.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"5a653cccf3a82189"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}