{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/badacts-a-universal-backdoor-defense-in-the","title":"BadActs: A Universal Backdoor Defense in the Activation Space","arxiv_id":"2405.11227","date":"2024-05-18","proceeding":null,"authors":["Biao Yi","Sishuo Chen","Yiming Li","Tong Li","Baolei Zhang","Zheli Liu"],"abstract":"Backdoor attacks pose an increasingly severe security threat to Deep Neural Networks (DNNs) during their development stage. In response, backdoor sample purification has emerged as a promising defense mechanism, aiming to eliminate backdoor triggers while preserving the integrity of the clean content in the samples. However, existing approaches have been predominantly focused on the word space, which are ineffective against feature-space triggers and significantly impair performance on clean data. To address this, we introduce a universal backdoor defense that purifies backdoor samples in the activation space by drawing abnormal activations towards optimized minimum clean activation distribution intervals. The advantages of our approach are twofold: (1) By operating in the activation space, our method captures from surface-level information like words to higher-level semantic concepts such as syntax, thus counteracting diverse triggers; (2) the fine-grained continuous nature of the activation space allows for more precise preservation of clean content while removing triggers. Furthermore, we propose a detection module based on statistical information of abnormal activations, to achieve a better trade-off between clean accuracy and defending performance.","url_abs":"https://arxiv.org/abs/2405.11227v1","url_pdf":"https://arxiv.org/pdf/2405.11227v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"badacts-a-universal-backdoor-defense-in-the","repo_url":"https://github.com/clearloveclearlove/BadActs","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok","spdx":"Apache-2.0"}}],"tasks":[{"task_slug":"backdoor-defense","task_name":"backdoor defense"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2405.11227","atlas_url":"https://app.syntology.ai/?focus=2405.11227","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2405.11227"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/clearloveclearlove/BadActs","reach":{"status":"ok","spdx":"Apache-2.0"}}],"summary":{"ran":3},"by_repo_kind":{"official":{"samples":3,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"b54ec27e47cab756","entry":"calculate_auroc","repo":"clearloveclearlove/BadActs","repo_kind":"official","path":"openbackdoor/defenders/badacts_defender.py","file_url":"https://github.com/clearloveclearlove/BadActs/blob/HEAD/openbackdoor/defenders/badacts_defender.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"Apache-2.0","inline_ok":true,"mcp_get_code":{"code_sha256":"b54ec27e47cab756"}},{"code_sha256_prefix":"93c0f4a3ea2d8466","entry":"calculate_pdf","repo":"clearloveclearlove/BadActs","repo_kind":"official","path":"openbackdoor/defenders/badacts_defender.py","file_url":"https://github.com/clearloveclearlove/BadActs/blob/HEAD/openbackdoor/defenders/badacts_defender.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":true,"licence":"Apache-2.0","inline_ok":true,"mcp_get_code":{"code_sha256":"93c0f4a3ea2d8466"}},{"code_sha256_prefix":"937794724e70d197","entry":"differential_entropy","repo":"clearloveclearlove/BadActs","repo_kind":"official","path":"openbackdoor/defenders/badacts_defender.py","file_url":"https://github.com/clearloveclearlove/BadActs/blob/HEAD/openbackdoor/defenders/badacts_defender.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":true,"licence":"Apache-2.0","inline_ok":true,"mcp_get_code":{"code_sha256":"937794724e70d197"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}