发表机构
University of Electronic Science and Technology of China(电子科技大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对后门攻击下的持续学习,提出融合样本净化、选择性恢复与鲁棒专家路由的动态扩展框架,兼顾抗遗忘、可塑性与安全性。
AI 中文摘要
持续学习(CL)使模型能够从顺序到达的任务中获取新知识,同时保留先前学到的知识。然而,在实际场景中,从不可信来源收集的任务流可能包含后门投毒样本,这对持续学习者的稳定性、可塑性和安全性构成了严峻挑战。在这项工作中,我们研究了一个具有挑战性的设置,称为后门攻击下的持续学习(CLUBA),其中每个增量任务可能包含一小部分恶意操纵的训练样本。与传统的持续学习或后门防御场景不同,CLUBA要求模型在顺序更新过程中同时缓解灾难性遗忘、保持适应能力,并防止吸收恶意监督。为了解决这一挑战,我们提出了一个鲁棒的动态扩展框架,将样本净化、选择性恢复和鲁棒专家路由整合到一个统一的持续学习范式中。具体来说,我们引入了双原型净化(BPP),通过利用特征空间中的语义差异来识别可疑样本。基于净化后的数据,基于梯度差异的鲁棒性优化(GDBRO)通过伪标签校正和梯度一致性评估选择性恢复信息丰富的投毒样本,在保持模型可塑性的同时提高鲁棒性。此外,基于鲁棒特征一致性的专家选择(RFCBES)构建了扰动感知的类原型,以在损坏或偏移的输入下实现可靠的专家路由。
英文摘要
Continual learning (CL) enables models to acquire new knowledge from sequentially arriving tasks while retaining previously learned knowledge. However, in practical scenarios, task streams collected from untrusted sources may contain backdoor-poisoned samples, posing a critical challenge to the stability, plasticity, and security of continual learners. In this work, we investigate a challenging setting termed Continual Learning Under Backdoor Attack (CLUBA), where each incremental task may involve a small proportion of maliciously manipulated training samples. Unlike conventional continual learning or backdoor defense scenarios, CLUBA requires models to simultaneously mitigate catastrophic forgetting, preserve adaptation capability, and prevent the absorption of malicious supervision during sequential updates. To address this challenge, we propose a robust dynamic-expansion framework that integrates sample purification, selective recovery, and robust expert routing into a unified continual learning paradigm. Specifically, we introduce Bi-Prototype Purification (BPP) to identify suspicious samples by exploiting semantic discrepancies in feature space. Based on purified data, Gradient Discrepancy-based Robustness Optimization (GDBRO) selectively recovers informative poisoned samples through pseudo-label correction and gradient consistency evaluation, improving robustness while maintaining model plasticity. Furthermore, Robust Feature Consistency-based Expert Selection (RFCBES) constructs perturbation-aware class prototypes to enable reliable expert routing under corrupted or shifted inputs.
Comments18 pages, 5 figures, 5 tables