A defense method against poisoning attacks for machine learning systems
By combining a contrastive learning framework with a supervised CFD method, the problem of identifying targeted clean-label poisoning attacks in existing technologies is solved. Effective defense is achieved under non-clean learning settings, improving the detection and defense capabilities of poisoned samples and expanding the application scope of the defense method.
CN118747825BActive Publication Date: 2026-05-29NAT UNIV OF DEFENSE TECH
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NAT UNIV OF DEFENSE TECH
- Filing Date
- 2024-07-18
- Publication Date
- 2026-05-29
Smart Images

Figure CN118747825B_ABST
Abstract
The application discloses a kind of defense methods for machine learning system poisoning attack, including steps: input image in training phase;Contrast loss, supervision loss and center discrimination loss are calculated;In test phase, input training set and filtering rate, calculate the prediction class label in the image in training set, and classify class center;According to ground truth score and center discrimination score, calculate total score, and rank data according to total score, filter contaminated data;Input actual image, use the model trained by the above steps to identify, and remove the sample of poisoning attack.The application integrates the concept of contrast learning to enhance feature representation, proposes a scoring strategy based on fusion to achieve more effective decision making;The application provides new benchmarks and new indicators to fully study the performance under non-clean settings.
Need to check novelty before this filing date? Find Prior Art