arXiv AI

Clustering Unsupervised Representations as Defense against Poisoning Attacks on Speech Commands Classification System

arXiv:2606. 28953v1 Announce Type: cross Abstract: Poisoning attacks entail attackers intentionally tampering with training data.

arXiv Machine Learning
1d ago

SAGE: Similarity-Based Cleaning of Poisoned Training Data from Verified Examples

SAGE is a defense against clean‑label data poisoning that relies on a very small set of verified examples—both clean and poisoned—rather than a large clean set. It trains a generic feature extractor on a separate dataset and then uses a non‑parametric, similarity‑weighted prediction to flag poisoned training examples. Experiments on standard benchmarks show that even a handful of verified poisoned examples give a substantial advantage, and that the distribution of verified clean examples across classes is more important than their sheer number.

By Chaeeun Han, Soodeh Atefi, Yevgeniy Vorobeychik, Aron Laszka
arXiv AI
2d ago

UniGuardian: A Unified Defense for Detecting Prompt Injection, Backdoor Attacks and Adversarial Attacks in Large Language Models

UniGuardian is a training‑free detector for large language models that jointly identifies prompt injection, backdoor, and adversarial attacks—collectively called Prompt Trigger Attacks (PTA). It measures how structured prompt perturbations shift the model’s output distribution and uses a single‑forward strategy to detect attacks while generating text in a shared batched forward pass. Experiments show that UniGuardian accurately and efficiently identifies trigger‑activated prompts in LLMs.

By Huawei Lin, Yingjie Lao, Tony Geng, Tan Yu, Weijie Zhao
arXiv Machine Learning
Sep 1

Learning diverse attacks on large language models for robust red-teaming and safety tuning

arXiv:2405.18540v3 Announce Type: replace-cross Abstract: Red-teaming, or identifying prompts that elicit harmful responses, is a critical step in ensuring the safe and responsible deployment of larg...

By Seanie Lee, Minsu Kim, Lynn Cherif, David Dobre, Juho Lee, Sung Ju Hwang, Kenji Kawaguchi, Gauthier Gidel, Yoshua Bengio, Esmeralda S. Whitammer, Moksh Jain
arXiv AI
Sep 3

Backdoor Attacks on Speech Emotion Recognition via TTS-Generated Poisoning

The paper investigates poisoning-based backdoor attacks on Speech Emotion Recognition (SER) systems that use self‑supervised acoustic representations. It introduces a stealthy, low‑energy acoustic trigger that can be embedded imperceptibly into both natural and synthetic speech, enabling scalable poisoning. Experiments show high attack success rates with low poisoning ratios, cross‑model transferability, and a particular vulnerability of self‑supervised representations, highlighting the lowered barrier to effective backdoor attacks via TTS technology.

By Yongbin Huang, Xihao Xie, Jia Zhang
arXiv AI
Sep 15

SynGhost: Invisible and Universal Task-agnostic Backdoor Attack via Syntactic Transfer

SynGhost is a novel task‑agnostic backdoor attack that injects invisible syntactic backdoors into pre‑training corpora of language models. It uses an entropy‑based poisoning filter, contrastive learning to select optimal targets, and an awareness module to reduce interference between backdoors, thereby preserving the model’s pre‑training performance. Experiments demonstrate that SynGhost can transfer to multiple downstream tasks and withstand several defense mechanisms such as perplexity checks, fine‑pruning, and the maxEntropy filter.

By Pengzhou Cheng, Wei Du, Zongru Wu, Fengwei Zhang, Libo Chen, Zhuosheng Zhang, Gongshen Liu