Related Experiment Video
Updated: Jul 17, 2026

In Vitro Selection of Aptamers to Differentiate Infectious from Non-Infectious Viruses
Published on: September 7, 2022
Dual-pathway mask ranking guided selective fine-tuning for backdoor purification
Rong Huang1, Xinming Cheng2, Isao Echizen3
1School of Information and Intelligent Science, Donghua University, Shanghai, 201620, China; Engineering Research Center of Digitized Textile and Fashion Technology, Ministry of Education, Donghua University, Shanghai, 201620, China.
Abstract:
A backdoor attack poisons a victim model during training, causing it to predict attacker-specified target label during inference. This has emerged as a critical threat to AI security. To counter this threat, backdoor purification seeks to eliminate or mitigate backdoor effect without compromising clean accuracy. Pruning-based methods alter the model architecture and degrade clean accuracy, while fine-tuning methods rarely explore backdoor-related cues, leaving residual backdoor effects. In this paper, we propose a dual-pathway mask ranking guided selective fine-tuning method for backdoor purification, synthesizing the perspectives of pruning and fine-tuning. Since clean-poisoned separation forms the data prerequisite for backdoor purification, we first develop an erasure-based intervention strategy grounded in our finding that backdoor-related triggers are prioritized for spatial reconstruction. This enables direct trigger erasure, making poisoned data more susceptible to erasure-based intervention than clean data. Building on this, we establish a forget-then-recover mechanism that characterizes the degree of backdoor contamination for each neuron using soft-valued masks. We design a training-free dual-pathway mask ranking module to categorize neurons into distinct types based on the rankings of soft-valued masks. This type information guides the selection of fine-tuning policies (i.e., relearning, unlearning or nolearning) for each neuron. Experimental results across four benchmark datasets (MNIST-M, SVHN, CIFAR-10, and CIFAR-100) demonstrate that our proposed method outperforms seven baseline competitors under various backdoor attacks. Our method attains the lowest average ASR (Attack Success Rate) ranging from 0.23% to 1.29%, and incurs the smallest average CA (Clean Accuracy) degradation ranging from 0.15% to 1.53%. Ablation studies further validate the effectiveness of our clean-poisoned separation strategy and selective fine-tuning policy.
Related Concept Videos
Masking and Demasking Agents
There are many masking agents, such as cyanide, fluoride, triethanolamine, thiourea, and 2,3-bis(sulfanyl)propan-1-ol (formerly 2,3-dimercapto-1-propanol), with the masking agent chosen based on the metal...
Detergent Purification of Membrane Proteins
