
객체 탐지기에 대한 백도어 공격을 손상, 확산 재구성, DBSCAN 합의 투표를 통해 무력화하는 블랙박스 입력 단계 정화 방어 기법.
객체 탐지기를 백도어 공격으로부터 방어하기 위해 특별히 설계된 최초의 입력 단계 블랙박스 정화 방어 기법.
ODPure는 객체 탐지기를 백도어 공격으로부터 방어하기 위해 특별히 설계된 최초의 입력 단계, 블랙박스 정화 프레임워크입니다. 이는 다음과 같은 새로운 손상-재구성-선택(Corruption-Reconstruction-Selection, CRS) 패러다임을 구현합니다:
ODPure는 다양한 백도어 공격을 효과적으로 무력화하여(공격 성공률을 최대 **0.0%**까지 감소) 깨끗한 탐지 유용성을 유지하며, 기존 방어 기법보다 우수한 방어-유용성 트레이드오프를 달성합니다.
# Core dependencies
torch>=1.13.0
torchvision>=0.14.0
numpy>=1.21.0
Pillow>=9.0.0
opencv-python>=4.5.0
# Diffusion models
diffusers>=0.14.0
transformers>=4.25.0
accelerate>=0.20.0
# Evaluation
scikit-learn>=1.2.0 # For DBSCAN clustering
scipy>=1.9.0
# Data processing
pyyaml>=6.0
tqdm>=4.64.0
# Create conda environment
conda create -n odpure python=3.9 -y
conda activate odpure
# Install PyTorch with CUDA
conda install pytorch torchvision pytorch-cuda=11.7 -c pytorch -c nvidia
# Install other dependencies
pip install -r requirements.txt
Reconstruction 모듈을 실행하기 전에 사전 학습된 모델 가중치를 다운로드해야 합니다:
mkdir -p Method/Reconstruction/weights
각 모델 저장소의 지침에 따라 가중치를 다운로드하고 배치합니다.
Method/Reconstruction/configs/의 구성 파일을 다운로드한 가중치를 가리키도록 업데이트합니다.
ODPure/
├── attack_script/ # Backdoor attack implementations
│ ├── COCO_chessboard_29x29_OMA.py # Object Misclassification (Chessboard)
│ ├── COCO_chessboard_29x29_ODA.py # Object Disappearance Attack (Chessboard)
│ ├── COCO_chessboard_9x9_OGA.py # Object Generation Attack (Chessboard)
│ ├── COCO_poke_15x15_OMA.py # OMA (Poké Ball)
│ ├── COCO_poke_15x15_ODA.py # ODA (Poké Ball)
│ ├── COCO_poke_15x15_OGA.py # OGA (Poké Ball)
│ ├── COCO_white_15x15_OMA.py # OMA (Solid White)
│ ├── COCO_white_15x15_ODA.py # ODA (Solid White)
│ └── COCO_white_15x15_OGA.py # OGA (Solid White)
│
├── Method/ # Core defense methodology
│ ├── corruptions/ # Image corruption module
│ │ ├── imagecorruption.py # Corruption functions
│ │ └── multiprocess_imagecorruption.py # Parallel processing
│ │
│ ├── Reconstruction/ # Diffusion-based restoration
│ │ ├── inference.py # Main inference script
│ │ ├── diffbir/ # DiffBIR model implementation
│ │ ├── llava/ # LLaVA captioner
│ │ ├── ram/ # Recognition-Aware Model
│ │ ├── configs/ # Model configurations
│ │ └── weights/ # Model weights (download separately)
│ │
│ └── dbscan_vote_new.py # DBSCAN clustering & voting
│
├── evaluation/ # Evaluation metrics
│ ├── OMA_ASR_new.py # OMA Attack Success Rate
│ ├── OMA_mAP.py # OMA Mean Average Precision
│ ├── ODA_ASR_new.py # ODA Attack Success Rate
│ ├── ODA_mAP.py # ODA Mean Average Precision
│ ├── OGA_ASR_new.py # OGA Attack Success Rate
│ ├── OGA_mAP.py # OGA Mean Average Precision
│ ├── val_OMA.py # YOLO validation for OMA
│ ├── val_ODA.py # YOLO validation for ODA
│ └── val_OGA.py # YOLO validation for OGA
│
├── data_format_conversion/ # Data format utilities
│ ├── voc2yolo.py # VOC to YOLO format conversion
│ ├── cocotoyolo.py # COCO to YOLO format conversion
│ └── select_coco_val_attack_information.py
│
├── ablation_study/ # Ablation experiments
│ ├── multiprocess_imagecorruption.py
│ ├── random_select_corruption.py
│ └── select_specific_corruption.py
│
├── run_pipeline.sh # One-shot CRS pipeline runner
└── README.md # This file
권장 진입점은 run_pipeline.sh이며, 이는 세 가지 CRS 단계를 연쇄적으로 실행합니다:
# Defaults: GPU=0, INPUT=inputs/demo/bid, OUTPUT=results/v2.1_demo_bid, ATTACK=ODA
bash run_pipeline.sh
# Custom arguments: GPU_ID INPUT_DIR OUTPUT_DIR ATTACK
bash run_pipeline.sh 0 inputs/coco_oda results/oda ODA
bash run_pipeline.sh 1 inputs/coco_oma results/oma OMA
bash run_pipeline.sh 2 inputs/coco_oga results/oga OGA
스크립트는 다음을 수행합니다:
최종 정화된 탐지 결과는 <OUTPUT_DIR>/final/에 기록됩니다.
중간 단계를 검사하거나 교체하려는 경우 사용하십시오.
python Method/corruptions/multiprocess_imagecorruption.py \
--input_dir /path/to/input/images \
--output_dir /path/to/corrupted/images \
--num_corruptions 45 \
--num_workers 8
python Method/Reconstruction/inference.py \
--task denoise \
--upscale 2 \
--version v2.1 \
--captioner llava \
--cfg_scale 6 \
--noise_aug 1 \
--input /path/to/corrupted/images \
--output /path/to/restored/images \
--batch_size 32 \
--device cuda
python Method/dbscan_vote_new.py \
--folder_purs /path/to/restored/detections \
--temp /path/to/temp \
--output_path /path/to/final/detections \
--eps 0.5 \
--min_samples 10
conda activate odpure
# Run on poisoned inputs (before defense)
python evaluation/val_ODA.py \
--weights runs/train/exp/weights/last.pt \
--data data/ODA_poison.yaml \
--img 640 --iou-thres 0.65 --conf-thres 0.5 \
--save-txt --save-conf \
--project results/poisoned_val_txt
# Run on clean inputs
python evaluation/val_ODA.py \
--weights runs/train/exp/weights/last.pt \
--data data/ODA_clean.yaml \
--img 640 --iou-thres 0.65 --conf-thres 0.5 \
--save-txt --save-conf \
--project results/clean_val_txt
# Run on purified inputs (after defense via ODPure)
python evaluation/val_ODA.py \
--weights runs/train/exp/weights/last.pt \
--data data/ODA_purified.yaml \
--img 640 --iou-thres 0.65 --conf-thres 0.5 \
--save-txt --save-conf \
--project results/pur_val_txt
python evaluation/OMA_ASR_new.py
스크립트 내부의 경로 구성:
gt_folder = "/path/to/ground_truth"
benign_folder = "/path/to/clean_val_txt"
attack_folder = "/path/to/pur_val_txt"
target_class = "0" # person class
python evaluation/ODA_ASR_new.py
python evaluation/OGA_ASR_new.py
python evaluation/ODA_mAP.py
python evaluation/OGA_mAP.py
python evaluation/OMA_mAP.py
ODPure는 4개 범주에 걸쳐 15가지 다양한 손상 함수를 사용합니다:
from Method.corruptions.imagecorruption import *
# Apply specific corruption
corrupted_img = gaussian_noise(image, severity=2)
corrupted_img = glass_blur(image, severity=1)
corrupted_img = jpeg_compression(image, severity=3)
# Process on specific GPU
CUDA_VISIBLE_DEVICES=0 python Method/Reconstruction/inference.py \
--task denoise --input inputs/demo --output results/demo
# Batch processing with multiple GPUs
CUDA_VISIBLE_DEVICES=0,1,2,3 python Method/Reconstruction/inference.py \
--task denoise --batch_size 64 --input inputs/batch --output results/batch
# Train backdoored model
CUDA_VISIBLE_DEVICES="0,1" python train.py \
--data data/custom.yaml \
--epochs 200 \
--weights checkpoints/yolov5s.pt \
--img 640 \
--batch-size 128
# Evaluate with defense
python evaluation/val_ODA.py \
--weights runs/train/exp/weights/last.pt \
--data data/val.yaml \
--img 640 \
--iou-thres 0.65 \
--conf-thres 0.5 \
--save-txt --save-conf
| 공격 유형 | 설명 | 동작 |
|---|---|---|
| OMA | 객체 오분류 공격 | 대상 객체를 강제로 오분류시킴 |
| ODA | 객체 소멸 공격 |
이 연구가 유용하다고 생각되면 다음을 인용해 주십시오:
@article{odpure2026,
title={ODPure: Backdoor Purification for Object Detection via Ensemble Corruption Consensus},
author={},
journal={},
year={2026}
}
이 프로젝트는 MIT 라이선스에 따라 라이선스가 부여됩니다 - 자세한 내용은 LICENSE 파일을 참조하십시오.
질문이나 협업을 원하시면 GitHub에 이슈를 열어주십시오.
ODPure - 연속적 인식을 유지하면서 객체 탐지 시스템을 백도어 공격으로부터 보호합니다.
| 모델 | 설명 | 다운로드 |
|---|
| DiffBIR v2.1 | 메인 복원 모델 | HuggingFace |
| Stable Diffusion | 잠재 확산 사전 | HuggingFace |
| LLaVA | 비전-언어 캡셔너 | HuggingFace |
| RAM | 인식 인식 모델 | GitHub Release |
| 매개변수 | 값 | 설명 |
|---|
num_corruptions | 15 types × 3 severities = 45 variants | 손상 다양성 |
corruption_severity | 1, 2, 3 | 손상 강도 수준 |
DBSCAN eps | 0.5 | 클러스터링 반경 |
DBSCAN min_samples | 10 | 합의 임계값 |
cfg_scale | 6.0 | 분류기 없는 가이던스 |
noise_aug | 1 | 노이즈 증강 수준 |
| 공격 | 데이터셋 (모델) | Clean mAP | 방어 전 (mAP/ASR) | 방어 후 (mAP/ASR) |
|---|
| OMA | VOC (YOLO) | 76.4% | 8.2% / 87.7% | 80.5% / 2.0% |
| OMA | VOC (F-RCNN) | 79.3% | 44.9% / 94.6% | 78.1% / 17.4% |
| OMA | COCO (YOLO) | 52.8% | 0.4% / 94.6% | 52.0% / 1.5% |
| OMA | COCO (F-RCNN) | 49.7% | 6.3% / 91.9% | 47.0% / 16.3% |
| ODA | VOC (YOLO) | 72.0% | 71.6% / 96.5% | 76.7% / 20.8% |
| ODA | VOC (F-RCNN) | 77.6% | 76.4% / 69.3% | 75.4% / 18.9% |
| ODA | COCO (YOLO) | 54.0% | 52.4% / 99.9% | 54.1% / 25.4% |
| ODA | COCO (F-RCNN) | 50.9% | 50.3% / 81.7% | 51.4% / 28.0% |
| OGA | VOC (YOLO) | 80.4% | 78.0% / 65.1% | 82.2% / 0.0% |
| OGA | VOC (F-RCNN) | 83.2% | 81.2% / 98.4% | 80.9% / 0.0% |
| OGA | COCO (YOLO) | 53.0% | 52.8% / 99.8% | 54.4% / 0.0% |
| OGA | COCO (F-RCNN) | 48.9% | 49.1% / 95.4% | 49.5% / 0.0% |
| 트리거 | 공격 | Clean mAP | 방어 전 ASR | 방어 후 ASR |
|---|
| Poké Ball | OMA | 77.3% | 95.5% | 19.8% |
| Poké Ball | ODA | 75.3% | 98.5% | 35.1% |
| Poké Ball | OGA | 79.8% | 96.8% | 15.4% |
| Solid White | OMA | 75.5% | 82.0% | 52.9% |
| Solid White | ODA | 71.8% | 71.1% | 44.0% |
| Solid White | OGA | 80.2% | 73.7% | 37.0% |
| 대상 객체가 탐지에서 사라지게 함 |
| OGA | 객체 생성 공격 | 환각된 유령 객체를 유도함 |