← Search

Zhuoran Liu

6 accepted papers

2024

BAN: Detecting Backdoors Activated by Adversarial Neuron Noise

NeurIPS 2024poster

Backdoor attacks on deep learning represent a recent threat that has gained significant attention in the research community. Backdoor defenses are mainly based on backdoor inversion, which has been shown to be generic, model-agnostic, and applicable to practical threat scenarios. State-of-the-art b…

2023

Beyond Neural-on-Neural Approaches to Speaker Gender Protection

ICASSP 2023accepted

Recent research has proposed approaches that modify speech to defend against gender inference attacks. The goal of these protection algorithms is to control the availability of information about a speaker’s gender, a privacy-sensitive attribute. Currently, the common practice for developing and test…

Cited by 0SourceScholar
2023

Image Shortcut Squeezing: Countering Perturbative Availability Poisons with Compression

ICML 2023poster

Perturbative availability poisoning (PAP) adds small changes to images to prevent their use for model training. Current research adopts the belief that practical and effective approaches to countering such poisons do not exist. In this paper, we argue that it is time to abandon this belief. We prese…

2023

Is Adversarial Training Really a Silver Bullet for Mitigating Data Poisoning?

ICLR 2023top-25%

Indiscriminate data poisoning can decrease the clean test accuracy of a deep learning model by slightly perturbing its training samples. There is a consensus that such poisons can hardly harm adversarially-trained (AT) models when the adversarial training budget is no less than the poison budget, i.…

2021

On Success and Simplicity: A Second Look at Transferable Targeted Attacks

NeurIPS 2021poster

Achieving transferability of targeted attacks is reputed to be remarkably difficult. The current state of the art has resorted to resource-intensive solutions that necessitate training model(s) for each target class with additional data. In our investigation, we find, however, that simple transferab…

2020

Towards Large Yet Imperceptible Adversarial Image Perturbations With Perceptual Color Distance

CVPR 2020poster

The success of image perturbations that are designed to fool image classifier is assessed in terms of both adversarial effect and visual imperceptibility. The conventional assumption on imperceptibility is that perturbations should strive for tight Lp-norm bounds in RGB space. In this work, we drop…

Cited by 179PDFcodeScholar