PapersWithELO
← ICLR 2024 leaderboard

Rethinking Backdoor Attacks on Dataset Distillation: A Kernel Method Perspective

Ming-Yu Chung, Sheng-Yen Chou, Chia-Mu Yu, Pin-Yu Chen, Sy-Yen Kuo, Tsung-Yi Ho

fairness, safety & privacyBackdoorTriggerDataset CondensationDataset Distillation
62.00100
Fused
band ≈ ±16 pct pts (from σ = 0.31)
51.30100
Mimo
band ≈ ±23 pct pts (from σ = 0.47)
61.90100
DeepSeek
band ≈ ±21 pct pts (from σ = 0.42)

OpenReview ground truth

Accepted

TL;DR — We theoretically analyze the backdoor attack using dataset condensation and then propose a trigger pattern generation algorithm.

Abstract

Dataset distillation offers a potential means to enhance data efficiency in deep learning. Recent studies have shown its ability to counteract backdoor risks present in original training samples. In this study, we delve into the theoretical aspects of backdoor attacks and dataset distillation based on kernel methods. We introduce two new theory-driven trigger pattern generation methods specialized for dataset distillation. Following a comprehensive set of analyses and experiments, we show that our optimization-based trigger design framework informs effective backdoor attacks on dataset distillation. Notably, datasets poisoned by our designed trigger prove resilient against conventional backdoor attack detection and mitigation methods. Our empirical results validate that the triggers developed using our approaches are proficient at executing resilient backdoor attacks.

Author context

Most prolific author: 18 submissions (credibility 0.86).

No mass-submission penalty for this paper (authors within normal submission volume).

Aggregate statistics only — no individual author rankings.

Ranking trajectory

Percentile by tournament round — convergence indicates rating stability.

Battle history — 34 comparisons

Ranked above opponent in 48% of matchups.

Judge assessments

Mean overall score 0.0 ± 0.0 (n = 34)