{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/the-beatrix-resurrections-robust-backdoor","title":"The \"Beatrix'' Resurrections: Robust Backdoor Detection via Gram Matrices","arxiv_id":"2209.11715","date":"2022-09-23","proceeding":null,"authors":["Wanlun Ma","Derui Wang","Ruoxi Sun","Minhui Xue","Sheng Wen","Yang Xiang"],"abstract":"Deep Neural Networks (DNNs) are susceptible to backdoor attacks during training. The model corrupted in this way functions normally, but when triggered by certain patterns in the input, produces a predefined target label. Existing defenses usually rely on the assumption of the universal backdoor setting in which poisoned samples share the same uniform trigger. However, recent advanced backdoor attacks show that this assumption is no longer valid in dynamic backdoors where the triggers vary from input to input, thereby defeating the existing defenses. In this work, we propose a novel technique, Beatrix (backdoor detection via Gram matrix). Beatrix utilizes Gram matrix to capture not only the feature correlations but also the appropriately high-order information of the representations. By learning class-conditional statistics from activation patterns of normal samples, Beatrix can identify poisoned samples by capturing the anomalies in activation patterns. To further improve the performance in identifying target labels, Beatrix leverages kernel-based testing without making any prior assumptions on representation distribution. We demonstrate the effectiveness of our method through extensive evaluation and comparison with state-of-the-art defensive techniques. The experimental results show that our approach achieves an F1 score of 91.1% in detecting dynamic backdoors, while the state of the art can only reach 36.9%.","url_abs":"https://arxiv.org/abs/2209.11715v3","url_pdf":"https://arxiv.org/pdf/2209.11715v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"the-beatrix-resurrections-robust-backdoor","repo_url":"https://github.com/wanlunsec/beatrix","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":null,"task_name":"valid"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2209.11715","atlas_url":"https://app.syntology.ai/?focus=2209.11715","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2209.11715"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/wanlunsec/beatrix","reach":null}],"summary":{"ran_draft_wrong":3,"ran_fixture":2},"by_repo_kind":{"official":{"samples":5,"ran":5,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":5,"samples":[{"code_sha256_prefix":"fce9e584c7bdef0a","entry":"create_bd","repo":"wanlunsec/beatrix","repo_kind":"official","path":"defenses/Beatrix/Beatrix.py","file_url":"https://github.com/wanlunsec/beatrix/blob/HEAD/defenses/Beatrix/Beatrix.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"fce9e584c7bdef0a"}},{"code_sha256_prefix":"93840db6e1795b76","entry":"create_cross","repo":"wanlunsec/beatrix","repo_kind":"official","path":"defenses/Beatrix/Beatrix.py","file_url":"https://github.com/wanlunsec/beatrix/blob/HEAD/defenses/Beatrix/Beatrix.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"93840db6e1795b76"}},{"code_sha256_prefix":"2172dd0a5f520f7d","entry":"create_targets_bd","repo":"wanlunsec/beatrix","repo_kind":"official","path":"defenses/Beatrix/Beatrix.py","file_url":"https://github.com/wanlunsec/beatrix/blob/HEAD/defenses/Beatrix/Beatrix.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"2172dd0a5f520f7d"}},{"code_sha256_prefix":"f7334fdb122d1c51","entry":"deprocess","repo":"wanlunsec/beatrix","repo_kind":"official","path":"defenses/ABS/abs_pytorch_round1.py","file_url":"https://github.com/wanlunsec/beatrix/blob/HEAD/defenses/ABS/abs_pytorch_round1.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"invariant","behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"f7334fdb122d1c51"}},{"code_sha256_prefix":"06fcb055d047c43d","entry":"preprocess","repo":"wanlunsec/beatrix","repo_kind":"official","path":"defenses/ABS/abs_pytorch_round1.py","file_url":"https://github.com/wanlunsec/beatrix/blob/HEAD/defenses/ABS/abs_pytorch_round1.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"invariant","behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"06fcb055d047c43d"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}