AuraTracer智迹闻
中文

EVENT DOSSIER

Leveraging Imperfect Restoration for Data Availability Attack

2026-09-07 12:00 Science 🔥 42.2 heat score
1sources
1days unfolding
42.2heat score
1mentions
SummaryAI generated

In response to the risk of online data being used for training deep learning models, researchers proposed a new attack method called Imperfect Recovery Poisoning (IRP). Existing convolutional-based non-learnable datasets (CUDA) perform well in supervised and self-supervised learning, but they are ineffective against self-supervised learning, and there is a serious trade-off between image quality and poisoning effect. This study revealed through theoretical analysis the strategies of introducing suboptimal gradients and inducing class bias in CUDA, and proposed the IRP method to achieve strong poisoning effects while maintaining high image quality. Experiments compared the performance of IRP with eight baseline methods in supervised and self-supervised learning, and verified it using five representative defense methods. The results showed that IRP was superior.

Related eventsRELATED EVENTS
Key entitiesKEY ENTITIES
arXiv

SignalsSIGNALS

Keyword heat
  • arXiv1

All reports (1)SOURCES

A arXiv cs.AI en 2026-09-07 12:00

Leveraging Imperfect Restoration for Data Availability Attack

针对在线数据被用于训练深度学习模型的风险,本文提出一种名为不完美恢复投毒(IRP)的新型方法。现有基于卷积的不可学习数据集(CUDA)虽在监督学习和自监督学习中表现稳健,但对抗自监督学习时效果不佳且存在图像质量与投毒效果的严重权衡。本研究通过理论分析揭示了 CUDA 引入次优梯度及诱导类别偏差的策略,并据此提出 IRP 以在保持高图像质量的同时实现强投毒效果。实验对比了 IRP 与八个基线方法在监督学习和自监督学习中的表现,并结合五种代表性防御方法进行验证,展示了 IRP 的优越性。