Test-Time Poisoned Sample Detection by Exploiting Shallow Malicious Matching in Backdoored CLIP
CLIP, known for its strong semantic matching capabilities derived from large-scale pretraining, has been shown to be vulnerable to backdoor attacks in prior work. In this work, we find that such attacks leave a detectable trace. This trace manifests as a divergence in how image features align with t…