Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Two Sides of the Same Coin: Learning the Backdoor to Remove the Backdoor

About

The community has recently developed various training-time defenses to counter neural backdoors introduced through data poisoning. In light of the observation that a model learns poisonous samples responsible for the backdoor easier than benign samples, these approaches either use a fixed threshold of the training loss for splitting or iteratively learn a reference model as an oracle for identifying benign samples. In particular, the latter has proven effective for anti-backdoor learning. Our method, HARVEY, leverages a similar yet crucially different technique: learning an oracle for poisonous rather than benign samples. Learning a backdoored reference model is significantly easier than learning a reference model on benign data. Consequently, we can identify poisonous samples much more accurately than related work identifies benign samples. This crucial difference enables near-perfect backdoor removal as we demonstrate in our evaluation. HARVEY substantially outperforms related approaches across attack types, datasets, and architectures, lowering the attack success rate to the very minimum at a negligible loss in natural accuracy. The figure below shows an overview of our methods working principle.

Qi Zhao, Christian Wressnegger• 2026

Related benchmarks

TaskDatasetResultRank
Backdoor DefenseTiny-ImageNet
Accuracy57.83
267
Image ClassificationGTSRB
Accuracy97.32
117
Backdoor DefenseCIFAR-10
Overall Accuracy93.96
108
Dataset Splitting for Backdoor DefenseGTSRB
Precision97.12
48
Backdoor Poisoning Sample IsolationCIFAR10 (train)
Precision83.04
48
Backdoor Poisoning Sample IsolationTiny-ImageNet (train)
Precision99.52
24
Showing 6 of 6 rows

Other info

Follow for update