{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/unit-backdoor-mitigation-via-automated-neural","title":"UNIT: Backdoor Mitigation via Automated Neural Distribution Tightening","arxiv_id":"2407.11372","date":"2024-07-16","proceeding":null,"authors":["Siyuan Cheng","Guangyu Shen","Kaiyuan Zhang","Guanhong Tao","Shengwei An","Hanxi Guo","Shiqing Ma","Xiangyu Zhang"],"abstract":"Deep neural networks (DNNs) have demonstrated effectiveness in various fields. However, DNNs are vulnerable to backdoor attacks, which inject a unique pattern, called trigger, into the input to cause misclassification to an attack-chosen target label. While existing works have proposed various methods to mitigate backdoor effects in poisoned models, they tend to be less effective against recent advanced attacks. In this paper, we introduce a novel post-training defense technique UNIT that can effectively eliminate backdoor effects for a variety of attacks. In specific, UNIT approximates a unique and tight activation distribution for each neuron in the model. It then proactively dispels substantially large activation values that exceed the approximated boundaries. Our experimental results demonstrate that UNIT outperforms 7 popular defense methods against 14 existing backdoor attacks, including 2 advanced attacks, using only 5\\% of clean training data. UNIT is also cost efficient. The code is accessible at https://github.com/Megum1/UNIT.","url_abs":"https://arxiv.org/abs/2407.11372v1","url_pdf":"https://arxiv.org/pdf/2407.11372v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"unit-backdoor-mitigation-via-automated-neural","repo_url":"https://github.com/megum1/unit","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok","spdx":"MIT"}}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":"https://app.syntology.ai/?focus=2407.11372","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2407.11372"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/megum1/unit","reach":{"status":"ok","spdx":"MIT"}}],"summary":{"ran":6},"by_repo_kind":{"official":{"samples":6,"ran":6,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"503dbc9905519b7c","entry":"activation_clip","repo":"megum1/unit","repo_kind":"official","path":"unit.py","file_url":"https://github.com/megum1/unit/blob/HEAD/unit.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":true,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"503dbc9905519b7c"}},{"code_sha256_prefix":"c72a4b5d656afd4d","entry":"eval_acc","repo":"megum1/unit","repo_kind":"official","path":"evaluate.py","file_url":"https://github.com/megum1/unit/blob/HEAD/evaluate.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"c72a4b5d656afd4d"}},{"code_sha256_prefix":"51385a626b151d0d","entry":"get_config","repo":"megum1/unit","repo_kind":"official","path":"utils.py","file_url":"https://github.com/megum1/unit/blob/HEAD/utils.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"51385a626b151d0d"}},{"code_sha256_prefix":"1959b01afae33059","entry":"get_norm","repo":"megum1/unit","repo_kind":"official","path":"utils.py","file_url":"https://github.com/megum1/unit/blob/HEAD/utils.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"1959b01afae33059"}},{"code_sha256_prefix":"4ed2471bba21c78d","entry":"get_transform","repo":"megum1/unit","repo_kind":"official","path":"utils.py","file_url":"https://github.com/megum1/unit/blob/HEAD/utils.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"4ed2471bba21c78d"}},{"code_sha256_prefix":"330ce598751fe949","entry":"validate_acc","repo":"megum1/unit","repo_kind":"official","path":"unit.py","file_url":"https://github.com/megum1/unit/blob/HEAD/unit.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"330ce598751fe949"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}