Leveraging Imperfect Restoration for Data Availability Attack
2026-09-07 12:00Science🔥 42.2 heat score
1sources
1days unfolding
42.2heat score
1mentions
SummaryAI generated
In response to the risk of online data being used for training deep learning models, researchers proposed a new attack method called Imperfect Recovery Poisoning (IRP). Existing convolutional-based non-learnable datasets (CUDA) perform well in supervised and self-supervised learning, but they are ineffective against self-supervised learning, and there is a serious trade-off between image quality and poisoning effect. This study revealed through theoretical analysis the strategies of introducing suboptimal gradients and inducing class bias in CUDA, and proposed the IRP method to achieve strong poisoning effects while maintaining high image quality. Experiments compared the performance of IRP with eight baseline methods in supervised and self-supervised learning, and verified it using five representative defense methods. The results showed that IRP was superior.