Method and system for defending backdoor attack based on attention mechanism and knowledge distillation
The invention discloses a method and a system for defending backdoor attack based on an attention mechanism and knowledge distillation, which are applied to the technical field of internet security, and the method comprises the following steps: a neural network fine tuning step: performing fine tuni...
Gespeichert in:
Hauptverfasser: | , , |
---|---|
Format: | Patent |
Sprache: | chi ; eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | The invention discloses a method and a system for defending backdoor attack based on an attention mechanism and knowledge distillation, which are applied to the technical field of internet security, and the method comprises the following steps: a neural network fine tuning step: performing fine tuning on a target neural network to obtain a fine-tuned deep neural network; an attention map generation step: mapping the output of each activation layer of the deep neural network to an attention map through an attention mapping operator; a model self-distillation step: performing knowledge self-distillation processing of the deep neural network layer by layer by using the attention map to obtain distillation loss between layers; and a defense module generation step: training through a model cross loss function to obtain a defense model. The backdoor attack can be effectively defended, and the defending effect is far better than that of a traditional method; and the method is more effective in the aspect of eliminat |
---|