← Search

Hailun Ding

2 accepted papers

2022

Rethinking the Reverse-engineering of Trojan Triggers

NeurIPS 2022accept

Deep Neural Networks are vulnerable to Trojan (or backdoor) attacks. Reverse-engineering methods can reconstruct the trigger and thus identify affected models. Existing reverse-engineering methods only consider input space constraints, e.g., trigger size in the input space. Expressly, they assume th…

2022

Training with More Confidence: Mitigating Injected and Natural Backdoors During Training

NeurIPS 2022accept

The backdoor or Trojan attack is a severe threat to deep neural networks (DNNs). Researchers find that DNNs trained on benign data and settings can also learn backdoor behaviors, which is known as the natural backdoor. Existing works on anti-backdoor learning are based on weak observations that the…