PapersWithELO
← ICLR 2024 leaderboard

Diffusion Denoising as a Certified Defense Against Clean-Label Poisoning Attacks

Sanghyun Hong, Nicholas Carlini, Alexey Kurakin

fairness, safety & privacyCertified defenseData poisoningDiffusion denoising
89.70100
Fused
band ≈ ±16 pct pts (from σ = 0.32)
91.60100
Mimo
band ≈ ±23 pct pts (from σ = 0.46)
86.70100
DeepSeek
band ≈ ±23 pct pts (from σ = 0.45)

OpenReview ground truth

Rejected

TL;DR — We show that our certified defense against data poisoning that leverages the diffusion denoising approach renders existing clean-label poisoning ineffective while preserving a model utility.

Abstract

We present a certified defense to clean-label poisoning attacks. These attacks work by injecting poisoning samples that contain $p$-norm bounded adversarial perturbations into the training data to induce a targeted misclassification of a test-time input. Inspired by the adversarial robustness achieved by $denoised$ $smoothing$, we show how a pre-trained diffusion model can sanitize the training data before a model training. We extensively test our defense against seven clean-label poisoning attacks and reduce their attack success to 0-16\% with only a small drop in the test time accuracy. We compare our defense with existing countermeasures against clean-label poisoning, showing that the defense reduces the attack success the most and offers the best model utility. Our results highlight the need for future work on developing stronger clean-label attacks and using our certified yet practical defense as a strong baseline to evaluate these attacks.

Author context

Most prolific author: 3 submissions (credibility 1.00).

No mass-submission penalty for this paper (authors within normal submission volume).

Aggregate statistics only — no individual author rankings.

Ranking trajectory

Percentile by tournament round — convergence indicates rating stability.

Judge assessments

Mean overall score 0.0 ± 0.0 (n = 32)