SSDA: Secure Source-Free Domain Adaptation

SSDA: Secure Source-Free Domain Adaptation
复制标题

DOI:
10.1109/iccv51070.2023.01757
复制
发表时间:
2023-10
期刊:
2023 IEEE/CVF International Conference on Computer Vision (ICCV)
影响因子:
--
通讯作者:
Sabbir Ahmed;Abdullah Al Arafat;M. N. Rizve;Rahim Hossain;Zhishan Guo;A. Rakin
Sabbir Ahmed;Abdullah Al Arafat;M. N. Rizve;Rahim Hossain;Zhishan Guo;A. Rakin
中科院分区:
其他
文献类型:
--
作者:
Sabbir Ahmed;Abdullah Al Arafat;M. N. Rizve;Rahim Hossain;Zhishan Guo;A. Rakin

文献摘要

相似文献

无源域自适应(SFDA)是一种流行的无监督域自适应方法,其中来自源域的预训练模型在不访问任何源数据的情况下适应目标域。尽管在这方面取得了丰富的成果,现有的文献忽略了安全挑战的无监督SFDA设置存在恶意源域所有者。这项工作调查的影响,源对手可能会注入一个隐藏的恶意行为(后门/木马)在源训练,并可能将其转移到目标域,即使经过良性训练的受害者(目标域所有者)。我们对SFDA当前环境的调查显示,由于SFDA面临的独特挑战(例如,没有源数据、目标标签),使用现有防御来防御后门攻击在保护目标模型方面变得实际上无效。为了解决这个问题,我们提出了一种新的目标域保护方案称为安全无源域自适应(SSDA)。SSDA采用预训练源模型的单次模型压缩和具有基于谱范数的损失惩罚的新型知识转移方案用于目标训练。所提出的静态压缩和动态训练损失惩罚的目的是抑制恶意通道响应后门在适应阶段。同时,未压缩的辅助模型的知识传递有助于恢复良性的测试精度。我们对多个数据集和域任务针对最近的后门攻击进行了广泛的评估,结果表明,与脆弱的基线SFDA方法相比,所提出的SSDA可以成功地抵御强大的后门攻击,并且测试精度几乎没有下降。我们的代码可在https://github.com/ML-Security-Research-LAB/SSDA上获得。
Source-free domain adaptation (SFDA) is a popular unsupervised domain adaptation method where a pre-trained model from a source domain is adapted to a target domain without accessing any source data. Despite rich results in this area, existing literature overlooks the security challenges of the unsupervised SFDA setting in presence of a malicious source domain owner. This work investigates the effect of a source adversary which may inject a hidden malicious behavior (Backdoor/Trojan) during source training and potentially transfer it to the target domain even after benign training by the victim (target domain owner). Our investigation of the current SFDA setting reveals that because of the unique challenges present in SFDA (e.g., no source data, target label), defending against backdoor attack using existing defenses become practically ineffective in protecting the target model. To address this, we propose a novel target domain protection scheme called secure source-free domain adaptation (SSDA). SSDA adopts a single-shot model compression of a pre-trained source model and a novel knowledge transfer scheme with a spectral-norm-based loss penalty for target training. The proposed static compression and the dynamic training loss penalty are designed to suppress the malicious channels responsive to the backdoor during the adaptation stage. At the same time, the knowledge transfer from an uncompressed auxiliary model helps to recover the benign test accuracy. Our extensive evaluation on multiple dataset and domain tasks against recent backdoor attacks reveal that the proposed SSDA can successfully defend against strong backdoor attacks with little to no degradation in test accuracy compared to the vulnerable baseline SFDA methods. Our code is available at https://github.com/ML-Security-Research-LAB/SSDA.