Adaptive Robust Learning Against Backdoor Attacks in Smart Homes
Jiahui Zhang, Zhuzhu Wang, Zhuoran Ma, Jianfeng Ma · IEEE Internet of Things Journal · 2024
Smart homes provide various services that serve people using AI (artificial intelligence) models. In order to meet the changing demands, devices in smart homes independently collect or passively receive data for model (re)training. However, backdoor attackers could inject backdoor samples into the training data set, thus controlling the behavior of devices by attaching a trigger to the input data. Robust learning methods attempt to achieve train backdoor-free models on untrusted datasets. In smart homes, models could have limited data sources or serve simple tasks, leading to poor performance of robust learning that isolates and unlearns backdoor samples based on loss value. In this paper, we propose a novel unlearn-based robust learning approach called Adaptive Robust Learning (ARL). Specifically, ARL applies a training epoch adaptive parameter to evaluate samples based on the decrease in the early training stage and the convergence in the late training stage of loss values. Furthermore, ARL employs a flexible isolation rule based on clustering to adjust the isolation rate dynamically, making it adaptive to the poisoning rate and reducing false isolation. Experimental results indicate that ARL outperforms our baseline in defending against backdoor attacks and is more applicable in smart home scenarios.