
物体検出器に特化した、バックドア攻撃に対する初の入力段階ブラックボックス浄化防御。
ODPure は、物体検出器をバックドア攻撃から防御するために特化した、初の入力段階・ブラックボックス浄化フレームワークです。これは、新しい Corruption-Reconstruction-Selection (CRS) パラダイムを実用化します:
ODPure は、多様なバックドア攻撃を効果的に無効化し(攻撃成功率を 0.0% まで低減)、クリーンな検出ユーティリティを維持しながら、既存の防御よりも優れた防御とユーティリティのトレードオフを実現します。
# Core dependencies
torch>=1.13.0
torchvision>=0.14.0
numpy>=1.21.0
Pillow>=9.0.0
opencv-python>=4.5.0
# Diffusion models
diffusers>=0.14.0
transformers>=4.25.0
accelerate>=0.20.0
# Evaluation
scikit-learn>=1.2.0 # For DBSCAN clustering
scipy>=1.9.0
# Data processing
pyyaml>=6.0
tqdm>=4.64.0
# Create conda environment
conda create -n odpure python=3.9 -y
conda activate odpure
# Install PyTorch with CUDA
conda install pytorch torchvision pytorch-cuda=11.7 -c pytorch -c nvidia
# Install other dependencies
pip install -r requirements.txt
Reconstruction モジュールを実行する前に、事前学習済みモデルの重みをダウンロードする必要があります:
mkdir -p Method/Reconstruction/weights
各モデルリポジトリの指示に従って、重みをダウンロードして配置します。
Method/Reconstruction/configs/ 内の設定ファイルを更新し、ダウンロードした重みを指すようにします。
ODPure/
├── attack_script/ # Backdoor attack implementations
│ ├── COCO_chessboard_29x29_OMA.py # Object Misclassification (Chessboard)
│ ├── COCO_chessboard_29x29_ODA.py # Object Disappearance Attack (Chessboard)
│ ├── COCO_chessboard_9x9_OGA.py # Object Generation Attack (Chessboard)
│ ├── COCO_poke_15x15_OMA.py # OMA (Poké Ball)
│ ├── COCO_poke_15x15_ODA.py # ODA (Poké Ball)
│ ├── COCO_poke_15x15_OGA.py # OGA (Poké Ball)
│ ├── COCO_white_15x15_OMA.py # OMA (Solid White)
│ ├── COCO_white_15x15_ODA.py # ODA (Solid White)
│ └── COCO_white_15x15_OGA.py # OGA (Solid White)
│
├── Method/ # Core defense methodology
│ ├── corruptions/ # Image corruption module
│ │ ├── imagecorruption.py # Corruption functions
│ │ └── multiprocess_imagecorruption.py # Parallel processing
│ │
│ ├── Reconstruction/ # Diffusion-based restoration
│ │ ├── inference.py # Main inference script
│ │ ├── diffbir/ # DiffBIR model implementation
│ │ ├── llava/ # LLaVA captioner
│ │ ├── ram/ # Recognition-Aware Model
│ │ ├── configs/ # Model configurations
│ │ └── weights/ # Model weights (download separately)
│ │
│ └── dbscan_vote_new.py # DBSCAN clustering & voting
│
├── evaluation/ # Evaluation metrics
│ ├── OMA_ASR_new.py # OMA Attack Success Rate
│ ├── OMA_mAP.py # OMA Mean Average Precision
│ ├── ODA_ASR_new.py # ODA Attack Success Rate
│ ├── ODA_mAP.py # ODA Mean Average Precision
│ ├── OGA_ASR_new.py # OGA Attack Success Rate
│ ├── OGA_mAP.py # OGA Mean Average Precision
│ ├── val_OMA.py # YOLO validation for OMA
│ ├── val_ODA.py # YOLO validation for ODA
│ └── val_OGA.py # YOLO validation for OGA
│
├── data_format_conversion/ # Data format utilities
│ ├── voc2yolo.py # VOC to YOLO format conversion
│ ├── cocotoyolo.py # COCO to YOLO format conversion
│ └── select_coco_val_attack_information.py
│
├── ablation_study/ # Ablation experiments
│ ├── multiprocess_imagecorruption.py
│ ├── random_select_corruption.py
│ └── select_specific_corruption.py
│
├── run_pipeline.sh # One-shot CRS pipeline runner
└── README.md # This file
推奨されるエントリポイントは run_pipeline.sh で、CRS の 3 つの段階を連鎖させます:
# Defaults: GPU=0, INPUT=inputs/demo/bid, OUTPUT=results/v2.1_demo_bid, ATTACK=ODA
bash run_pipeline.sh
# Custom arguments: GPU_ID INPUT_DIR OUTPUT_DIR ATTACK
bash run_pipeline.sh 0 inputs/coco_oda results/oda ODA
bash run_pipeline.sh 1 inputs/coco_oma results/oma OMA
bash run_pipeline.sh 2 inputs/coco_oga results/oga OGA
このスクリプトは以下を実行します:
最終的な浄化済み検出結果は <OUTPUT_DIR>/final/ に書き出されます。
中間ステップを検査・置き換えたい場合に使用します。
python Method/corruptions/multiprocess_imagecorruption.py \
--input_dir /path/to/input/images \
--output_dir /path/to/corrupted/images \
--num_corruptions 45 \
--num_workers 8
python Method/Reconstruction/inference.py \
--task denoise \
--upscale 2 \
--version v2.1 \
--captioner llava \
--cfg_scale 6 \
--noise_aug 1 \
--input /path/to/corrupted/images \
--output /path/to/restored/images \
--batch_size 32 \
--device cuda
python Method/dbscan_vote_new.py \
--folder_purs /path/to/restored/detections \
--temp /path/to/temp \
--output_path /path/to/final/detections \
--eps 0.5 \
--min_samples 10
conda activate odpure
# Run on poisoned inputs (before defense)
python evaluation/val_ODA.py \
--weights runs/train/exp/weights/last.pt \
--data data/ODA_poison.yaml \
--img 640 --iou-thres 0.65 --conf-thres 0.5 \
--save-txt --save-conf \
--project results/poisoned_val_txt
# Run on clean inputs
python evaluation/val_ODA.py \
--weights runs/train/exp/weights/last.pt \
--data data/ODA_clean.yaml \
--img 640 --iou-thres 0.65 --conf-thres 0.5 \
--save-txt --save-conf \
--project results/clean_val_txt
# Run on purified inputs (after defense via ODPure)
python evaluation/val_ODA.py \
--weights runs/train/exp/weights/last.pt \
--data data/ODA_purified.yaml \
--img 640 --iou-thres 0.65 --conf-thres 0.5 \
--save-txt --save-conf \
--project results/pur_val_txt
python evaluation/OMA_ASR_new.py
スクリプト内のパスを設定します:
gt_folder = "/path/to/ground_truth"
benign_folder = "/path/to/clean_val_txt"
attack_folder = "/path/to/pur_val_txt"
target_class = "0" # person class
python evaluation/ODA_ASR_new.py
python evaluation/OGA_ASR_new.py
python evaluation/ODA_mAP.py
python evaluation/OGA_mAP.py
python evaluation/OMA_mAP.py
ODPure は、4 つのカテゴリにわたる 15 種類の多様な汚染関数を使用します:
from Method.corruptions.imagecorruption import *
# Apply specific corruption
corrupted_img = gaussian_noise(image, severity=2)
corrupted_img = glass_blur(image, severity=1)
corrupted_img = jpeg_compression(image, severity=3)
# Process on specific GPU
CUDA_VISIBLE_DEVICES=0 python Method/Reconstruction/inference.py \
--task denoise --input inputs/demo --output results/demo
# Batch processing with multiple GPUs
CUDA_VISIBLE_DEVICES=0,1,2,3 python Method/Reconstruction/inference.py \
--task denoise --batch_size 64 --input inputs/batch --output results/batch
# Train backdoored model
CUDA_VISIBLE_DEVICES="0,1" python train.py \
--data data/custom.yaml \
--epochs 200 \
--weights checkpoints/yolov5s.pt \
--img 640 \
--batch-size 128
# Evaluate with defense
python evaluation/val_ODA.py \
--weights runs/train/exp/weights/last.pt \
--data data/val.yaml \
--img 640 \
--iou-thres 0.65 \
--conf-thres 0.5 \
--save-txt --save-conf
| 攻撃タイプ | 説明 | 挙動 |
|---|---|---|
| OMA | Object Misclassification Attack | 対象物体を強制的に誤分類させる |
この研究があなたの研究に役立つ場合は、以下を引用してください:
@article{odpure2026,
title={ODPure: Backdoor Purification for Object Detection via Ensemble Corruption Consensus},
author={},
journal={},
year={2026}
}
このプロジェクトは MIT ライセンスの下でライセンスされています - 詳細は LICENSE ファイルを参照してください。
質問や共同研究については、GitHub で issue を作成してください。
ODPure - 連続知覚を維持しながら、物体検出システムをバックドア攻撃から保護します。
| モデル | 説明 | ダウンロード |
|---|
| DiffBIR v2.1 | メイン復元モデル | HuggingFace |
| Stable Diffusion | 潜在拡散事前分布 | HuggingFace |
| LLaVA | 視覚言語キャプショナー | HuggingFace |
| RAM | Recognition-Aware Model | GitHub Release |
| パラメータ | 値 | 説明 |
|---|
num_corruptions | 15 種類 × 3 深刻度 = 45 バリアント | 汚染の多様性 |
corruption_severity | 1, 2, 3 | 汚染強度レベル |
DBSCAN eps | 0.5 | クラスタリング半径 |
DBSCAN min_samples | 10 | コンセンサス閾値 |
cfg_scale | 6.0 | 分類器フリーガイダンス |
noise_aug | 1 | ノイズ拡張レベル |
| 攻撃 | データセット(モデル) | クリーン mAP | 防御前 (mAP/ASR) | 防御後 (mAP/ASR) |
|---|
| OMA | VOC (YOLO) | 76.4% | 8.2% / 87.7% | 80.5% / 2.0% |
| OMA | VOC (F-RCNN) | 79.3% | 44.9% / 94.6% | 78.1% / 17.4% |
| OMA | COCO (YOLO) | 52.8% | 0.4% / 94.6% | 52.0% / 1.5% |
| OMA | COCO (F-RCNN) | 49.7% | 6.3% / 91.9% | 47.0% / 16.3% |
| ODA | VOC (YOLO) | 72.0% | 71.6% / 96.5% | 76.7% / 20.8% |
| ODA | VOC (F-RCNN) | 77.6% | 76.4% / 69.3% | 75.4% / 18.9% |
| ODA | COCO (YOLO) | 54.0% | 52.4% / 99.9% | 54.1% / 25.4% |
| ODA | COCO (F-RCNN) | 50.9% | 50.3% / 81.7% | 51.4% / 28.0% |
| OGA | VOC (YOLO) | 80.4% | 78.0% / 65.1% | 82.2% / 0.0% |
| OGA | VOC (F-RCNN) | 83.2% | 81.2% / 98.4% | 80.9% / 0.0% |
| OGA | COCO (YOLO) | 53.0% | 52.8% / 99.8% | 54.4% / 0.0% |
| OGA | COCO (F-RCNN) | 48.9% | 49.1% / 95.4% | 49.5% / 0.0% |
| トリガー | 攻撃 | クリーン mAP | 防御前 ASR | 防御後 ASR |
|---|
| モンスターボール | OMA | 77.3% | 95.5% | 19.8% |
| モンスターボール | ODA | 75.3% | 98.5% | 35.1% |
| モンスターボール | OGA | 79.8% | 96.8% | 15.4% |
| 純白 | OMA | 75.5% | 82.0% | 52.9% |
| 純白 | ODA | 71.8% | 71.1% | 44.0% |
| 純白 | OGA | 80.2% | 73.7% | 37.0% |
| ODA |
| Object Disappearance Attack |
| 対象物体を検出から消滅させる |
| OGA | Object Generation Attack | 幻のゴースト物体を誘発する |