{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/spectral-signatures-in-backdoor-attacks","title":"Spectral Signatures in Backdoor Attacks","arxiv_id":"1811.00636","date":"2018-11-01","proceeding":"NeurIPS 2018 12","authors":["Brandon Tran","Jerry Li","Aleksander Madry"],"abstract":"A recent line of work has uncovered a new form of data poisoning: so-called\n\\emph{backdoor} attacks. These attacks are particularly dangerous because they\ndo not affect a network's behavior on typical, benign data. Rather, the network\nonly deviates from its expected output when triggered by a perturbation planted\nby an adversary.\n  In this paper, we identify a new property of all known backdoor attacks,\nwhich we call \\emph{spectral signatures}. This property allows us to utilize\ntools from robust statistics to thwart the attacks. We demonstrate the efficacy\nof these signatures in detecting and removing poisoned examples on real image\nsets and state of the art neural network architectures. We believe that\nunderstanding spectral signatures is a crucial first step towards designing ML\nsystems secure against such backdoor attacks","url_abs":"http://arxiv.org/abs/1811.00636v1","url_pdf":"http://arxiv.org/pdf/1811.00636v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"spectral-signatures-in-backdoor-attacks","repo_url":"https://github.com/bxz9200/ultraclean","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}}],"tasks":[{"task_slug":"data-poisoning","task_name":"Data Poisoning"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1811.00636","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}