Beyond Small Patches: Black-Box Detection and Purification of Diverse Backdoor Triggers
New black-box defence detects and purifies diverse backdoor triggers in DNNs, moving beyond the small-patch assumption that limits most existing methods—relevant for enterprises deploying third-party vision models.
Summary written by editorial AI · Source link below
arXiv:2609.03139v1 Announce Type: cross Abstract: Deep neural networks (DNNs) are increasingly deployed in real-world vision systems, yet their predictions can be covertly manipulated by backdoor attacks, in which malicious triggers cause targeted misclassification while preserving high clean accuracy. Existing defenses often rely on model internals, training data, or clean validation samples, making them difficult to deploy when only black-box access to a trained model is available. We propose
Editorial Analysis
Enterprises consuming pre-trained vision models face supply-chain backdoor risk; broader trigger coverage in detection methods reduces the chance of a compromised model reaching production.
Integrate diverse-trigger backdoor scanning into your model-acceptance testing pipeline for any externally sourced DNN.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the AI Security Desk
- OpenAI admits it didn't disclose rogue AI wiki hijacking incident2d
- Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel3d
- Using a VM to Contain an AI Agent3d
- Companies Have 6 Months to Prepare for Automated Attacks3d
- [NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen3d