首个针对目标检测器的输入阶段黑盒净化防御,用于抵御后门攻击。
ODPure 是首个专为目标检测器抵御后门攻击而设计的输入阶段、黑盒净化框架。它实现了一种新颖的 损坏-重建-选择(Corruption-Reconstruction-Selection, CRS) 范式,该范式:
ODPure 有效中和了多种后门攻击(将攻击成功率降至低至 0.0%),同时保持干净的检测效用,相比现有防御方法实现了更优的防御-效用权衡。
# Core dependencies
torch>=1.13.0
torchvision>=0.14.0
numpy>=1.21.0
Pillow>=9.0.0
opencv-python>=4.5.0
# Diffusion models
diffusers>=0.14.0
transformers>=4.25.0
accelerate>=0.20.0
# Evaluation
scikit-learn>=1.2.0 # For DBSCAN clustering
scipy>=1.9.0
# Data processing
pyyaml>=6.0
tqdm>=4.64.0
# Create conda environment
conda create -n odpure python=3.9 -y
conda activate odpure
# Install PyTorch with CUDA
conda install pytorch torchvision pytorch-cuda=11.7 -c pytorch -c nvidia
# Install other dependencies
pip install -r requirements.txt
在运行重建模块之前,您需要下载预训练模型权重:
mkdir -p Method/Reconstruction/weights
按照各自模型仓库中的说明下载并放置权重。
更新 Method/Reconstruction/configs/ 中的配置文件,使其指向您下载的权重。
ODPure/
├── attack_script/ # Backdoor attack implementations
│ ├── COCO_chessboard_29x29_OMA.py # Object Misclassification (Chessboard)
│ ├── COCO_chessboard_29x29_ODA.py # Object Disappearance Attack (Chessboard)
│ ├── COCO_chessboard_9x9_OGA.py # Object Generation Attack (Chessboard)
│ ├── COCO_poke_15x15_OMA.py # OMA (Poké Ball)
│ ├── COCO_poke_15x15_ODA.py # ODA (Poké Ball)
│ ├── COCO_poke_15x15_OGA.py # OGA (Poké Ball)
│ ├── COCO_white_15x15_OMA.py # OMA (Solid White)
│ ├── COCO_white_15x15_ODA.py # ODA (Solid White)
│ └── COCO_white_15x15_OGA.py # OGA (Solid White)
│
├── Method/ # Core defense methodology
│ ├── corruptions/ # Image corruption module
│ │ ├── imagecorruption.py # Corruption functions
│ │ └── multiprocess_imagecorruption.py # Parallel processing
│ │
│ ├── Reconstruction/ # Diffusion-based restoration
│ │ ├── inference.py # Main inference script
│ │ ├── diffbir/ # DiffBIR model implementation
│ │ ├── llava/ # LLaVA captioner
│ │ ├── ram/ # Recognition-Aware Model
│ │ ├── configs/ # Model configurations
│ │ └── weights/ # Model weights (download separately)
│ │
│ └── dbscan_vote_new.py # DBSCAN clustering & voting
│
├── evaluation/ # Evaluation metrics
│ ├── OMA_ASR_new.py # OMA Attack Success Rate
│ ├── OMA_mAP.py # OMA Mean Average Precision
│ ├── ODA_ASR_new.py # ODA Attack Success Rate
│ ├── ODA_mAP.py # ODA Mean Average Precision
│ ├── OGA_ASR_new.py # OGA Attack Success Rate
│ ├── OGA_mAP.py # OGA Mean Average Precision
│ ├── val_OMA.py # YOLO validation for OMA
│ ├── val_ODA.py # YOLO validation for ODA
│ └── val_OGA.py # YOLO validation for OGA
│
├── data_format_conversion/ # Data format utilities
│ ├── voc2yolo.py # VOC to YOLO format conversion
│ ├── cocotoyolo.py # COCO to YOLO format conversion
│ └── select_coco_val_attack_information.py
│
├── ablation_study/ # Ablation experiments
│ ├── multiprocess_imagecorruption.py
│ ├── random_select_corruption.py
│ └── select_specific_corruption.py
│
├── run_pipeline.sh # One-shot CRS pipeline runner
└── README.md # This file
推荐的入口点是 run_pipeline.sh,它级联执行 CRS 的三个阶段:
# Defaults: GPU=0, INPUT=inputs/demo/bid, OUTPUT=results/v2.1_demo_bid, ATTACK=ODA
bash run_pipeline.sh
# Custom arguments: GPU_ID INPUT_DIR OUTPUT_DIR ATTACK
bash run_pipeline.sh 0 inputs/coco_oda results/oda ODA
bash run_pipeline.sh 1 inputs/coco_oma results/oma OMA
bash run_pipeline.sh 2 inputs/coco_oga results/oga OGA
该脚本执行:
最终净化后的检测结果写入 <OUTPUT_DIR>/final/。
如果您想检查/替换中间步骤,请使用此选项。
python Method/corruptions/multiprocess_imagecorruption.py \
--input_dir /path/to/input/images \
--output_dir /path/to/corrupted/images \
--num_corruptions 45 \
--num_workers 8
python Method/Reconstruction/inference.py \
--task denoise \
--upscale 2 \
--version v2.1 \
--captioner llava \
--cfg_scale 6 \
--noise_aug 1 \
--input /path/to/corrupted/images \
--output /path/to/restored/images \
--batch_size 32 \
--device cuda
python Method/dbscan_vote_new.py \
--folder_purs /path/to/restored/detections \
--temp /path/to/temp \
--output_path /path/to/final/detections \
--eps 0.5 \
--min_samples 10
conda activate odpure
# Run on poisoned inputs (before defense)
python evaluation/val_ODA.py \
--weights runs/train/exp/weights/last.pt \
--data data/ODA_poison.yaml \
--img 640 --iou-thres 0.65 --conf-thres 0.5 \
--save-txt --save-conf \
--project results/poisoned_val_txt
# Run on clean inputs
python evaluation/val_ODA.py \
--weights runs/train/exp/weights/last.pt \
--data data/ODA_clean.yaml \
--img 640 --iou-thres 0.65 --conf-thres 0.5 \
--save-txt --save-conf \
--project results/clean_val_txt
# Run on purified inputs (after defense via ODPure)
python evaluation/val_ODA.py \
--weights runs/train/exp/weights/last.pt \
--data data/ODA_purified.yaml \
--img 640 --iou-thres 0.65 --conf-thres 0.5 \
--save-txt --save-conf \
--project results/pur_val_txt
python evaluation/OMA_ASR_new.py
在脚本内配置路径:
gt_folder = "/path/to/ground_truth"
benign_folder = "/path/to/clean_val_txt"
attack_folder = "/path/to/pur_val_txt"
target_class = "0" # person class
python evaluation/ODA_ASR_new.py
python evaluation/OGA_ASR_new.py
python evaluation/ODA_mAP.py
python evaluation/OGA_mAP.py
python evaluation/OMA_mAP.py
ODPure 使用 4 个类别下的 15 种多样化损坏函数:
from Method.corruptions.imagecorruption import *
# Apply specific corruption
corrupted_img = gaussian_noise(image, severity=2)
corrupted_img = glass_blur(image, severity=1)
corrupted_img = jpeg_compression(image, severity=3)
# Process on specific GPU
CUDA_VISIBLE_DEVICES=0 python Method/Reconstruction/inference.py \
--task denoise --input inputs/demo --output results/demo
# Batch processing with multiple GPUs
CUDA_VISIBLE_DEVICES=0,1,2,3 python Method/Reconstruction/inference.py \
--task denoise --batch_size 64 --input inputs/batch --output results/batch
# Train backdoored model
CUDA_VISIBLE_DEVICES="0,1" python train.py \
--data data/custom.yaml \
--epochs 200 \
--weights checkpoints/yolov5s.pt \
--img 640 \
--batch-size 128
# Evaluate with defense
python evaluation/val_ODA.py \
--weights runs/train/exp/weights/last.pt \
--data data/val.yaml \
--img 640 \
--iou-thres 0.65 \
--conf-thres 0.5 \
--save-txt --save-conf
| 攻击类型 | 描述 | 行为 |
|---|---|---|
| OMA | 目标误分类攻击 | 迫使目标对象被误分类 |
| ODA | 目标消失攻击 | 导致目标对象从检测中消失 |
如果您发现这项工作对您的研究有用,请引用:
@article{odpure2026,
title={ODPure: Backdoor Purification for Object Detection via Ensemble Corruption Consensus},
author={},
journal={},
year={2026}
}
本项目采用 MIT 许可证 - 详情请参阅 LICENSE 文件。
如有问题或合作意向,请在 GitHub 上提交 issue。
ODPure - 保护目标检测系统免受后门攻击,同时保持连续感知。
| 模型 | 描述 | 下载 |
|---|
| DiffBIR v2.1 | 主恢复模型 | HuggingFace |
| Stable Diffusion | 潜在扩散先验 | HuggingFace |
| LLaVA | 视觉-语言描述器 | HuggingFace |
| RAM | 识别感知模型 | GitHub Release |
| 参数 | 值 | 描述 |
|---|
num_corruptions | 15 种类型 × 3 个严重程度 = 45 个变体 | 损坏多样性 |
corruption_severity | 1, 2, 3 | 损坏强度级别 |
DBSCAN eps | 0.5 | 聚类半径 |
DBSCAN min_samples | 10 | 共识阈值 |
cfg_scale | 6.0 | 无分类器引导 |
noise_aug | 1 | 噪声增强级别 |
| 攻击 | 数据集(模型) | 干净 mAP | 防御前(mAP/ASR) | 防御后(mAP/ASR) |
|---|
| OMA | VOC (YOLO) | 76.4% | 8.2% / 87.7% | 80.5% / 2.0% |
| OMA | VOC (F-RCNN) | 79.3% | 44.9% / 94.6% | 78.1% / 17.4% |
| OMA | COCO (YOLO) | 52.8% | 0.4% / 94.6% | 52.0% / 1.5% |
| OMA | COCO (F-RCNN) | 49.7% | 6.3% / 91.9% | 47.0% / 16.3% |
| ODA | VOC (YOLO) | 72.0% | 71.6% / 96.5% | 76.7% / 20.8% |
| ODA | VOC (F-RCNN) | 77.6% | 76.4% / 69.3% | 75.4% / 18.9% |
| ODA | COCO (YOLO) | 54.0% | 52.4% / 99.9% | 54.1% / 25.4% |
| ODA | COCO (F-RCNN) | 50.9% | 50.3% / 81.7% | 51.4% / 28.0% |
| OGA | VOC (YOLO) | 80.4% | 78.0% / 65.1% | 82.2% / 0.0% |
| OGA | VOC (F-RCNN) | 83.2% | 81.2% / 98.4% | 80.9% / 0.0% |
| OGA | COCO (YOLO) | 53.0% | 52.8% / 99.8% | 54.4% / 0.0% |
| OGA | COCO (F-RCNN) | 48.9% | 49.1% / 95.4% | 49.5% / 0.0% |
| 触发器 | 攻击 | 干净 mAP | 防御前 ASR | 防御后 ASR |
|---|
| 精灵球 | OMA | 77.3% | 95.5% | 19.8% |
| 精灵球 | ODA | 75.3% | 98.5% | 35.1% |
| 精灵球 | OGA | 79.8% | 96.8% | 15.4% |
| 纯白色 | OMA | 75.5% | 82.0% | 52.9% |
| 纯白色 | ODA | 71.8% | 71.1% | 44.0% |
| 纯白色 | OGA | 80.2% | 73.7% | 37.0% |
| OGA | 目标生成攻击 | 诱导产生幻觉幽灵对象 |