← Search

Mingli Zhu

7 accepted papers

2026

Reliable Poisoned Sample Detection against Backdoor Attacks Enhanced by Sharpness Aware Minimization

ICLR 2026poster

This work investigates Poisoned Sample Detection (PSD), a promising defense approach against backdoor attacks. However, we observe that the effectiveness of many advanced PSD methods degrades significantly under weak backdoor attacks (\eg, low poisoning ratios or weak trigger patterns). To substanti…

Cited by 0SourceScholar
2025

BadVideo: Stealthy Backdoor Attack against Text-to-Video Generation

ICCV 2025poster

Text-to-video (T2V) generative models have rapidly advanced and found widespread applications across fields like entertainment, education, and marketing. However, the adversarial vulnerabilities of these models remain rarely explored. We observe that in T2V generation tasks, the generated videos oft…

2025

Revisiting Backdoor Attacks against Large Vision-Language Models from Domain Shift

CVPR 2025poster

Instruction tuning enhances large vision-language models (LVLMs) but increases their vulnerability to backdoor attacks due to their open design. Unlike prior studies in static settings, this paper explores backdoor attacks in LVLM instruction tuning across mismatched training and testing domains. We…

2024

BadCLIP: Dual-Embedding Guided Backdoor Attack on Multimodal Contrastive Learning

CVPR 2024highlight

While existing backdoor attacks have successfully infected multimodal contrastive learning models such as CLIP they can be easily countered by specialized backdoor defenses for MCL models. This paper reveals the threats in this practical scenario and introduces the BadCLIP attack which is resistant…

2024

Breaking the False Sense of Security in Backdoor Defense through Re-Activation Attack

NeurIPS 2024poster

Deep neural networks face persistent challenges in defending against backdoor attacks, leading to an ongoing battle between attacks and defenses. While existing backdoor defense strategies have shown promising performance on reducing attack success rates, can we confidently claim that the backdoor t…

Cited by 14SourcePDFScholar
2023

Enhancing Fine-Tuning Based Backdoor Defense with Sharpness-Aware Minimization

ICCV 2023poster

Backdoor defense, which aims to detect or mitigate the effect of malicious triggers introduced by attackers, is becoming increasingly critical for machine learning security and integrity. Fine-tuning based on benign data is a natural defense to erase the backdoor effect in a backdoored model. Howeve…

Cited by 66PDFcodeScholar
2023

Neural Polarizer: A Lightweight and Effective Backdoor Defense via Purifying Poisoned Features

NeurIPS 2023poster

Recent studies have demonstrated the susceptibility of deep neural networks to backdoor attacks. Given a backdoored model, its prediction of a poisoned sample with trigger will be dominated by the trigger information, though trigger information and benign information coexist. Inspired by the mechani…