A defense method against poisoning attacks for machine learning systems

By combining a contrastive learning framework with a supervised CFD method, the problem of identifying targeted clean-label poisoning attacks in existing technologies is solved. Effective defense is achieved under non-clean learning settings, improving the detection and defense capabilities of poisoned samples and expanding the application scope of the defense method.

CN118747825BActive Publication Date: 2026-05-29NAT UNIV OF DEFENSE TECH

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NAT UNIV OF DEFENSE TECH
Filing Date
2024-07-18
Publication Date
2026-05-29

Smart Images

  • Figure CN118747825B_ABST
    Figure CN118747825B_ABST
Patent Text Reader

Abstract

The application discloses a kind of defense methods for machine learning system poisoning attack, including steps: input image in training phase;Contrast loss, supervision loss and center discrimination loss are calculated;In test phase, input training set and filtering rate, calculate the prediction class label in the image in training set, and classify class center;According to ground truth score and center discrimination score, calculate total score, and rank data according to total score, filter contaminated data;Input actual image, use the model trained by the above steps to identify, and remove the sample of poisoning attack.The application integrates the concept of contrast learning to enhance feature representation, proposes a scoring strategy based on fusion to achieve more effective decision making;The application provides new benchmarks and new indicators to fully study the performance under non-clean settings.
Need to check novelty before this filing date? Find Prior Art