[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-121013-en":3,"doc-seo-121013-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},121013,5909877438554,"Maeve","https://ap-avatar.wpscdn.com/avatar/5600025385ad2bf12a7?_k=1778553567797529272",8,"Research & Report","Backdoor Learning Curves - Explaining Backdoor Poisoning Beyond Influence Functions","Backdoor attacks insert poisoning samples during training so a model reliably predicts an attacker-chosen target class whenever a specified trigger appears at test time. Despite extensive demonstrations across scenarios and model types, the determinants of attack success remain unclear. This work proposes a unified framework connecting backdoor learning to incremental learning and influence functions. The analysis shows success depends on learning complexity via hyperparameters and the injected backdoor fraction. A hyperparameter region preserves clean accuracy while weakening backdoor effectiveness, supporting new defense criteria.","Backdoor Learning Curves: Explaining Backdoor Poisoning Beyond Inﬂuence Functions  \narXiv :2106 .07214v1 [ cs .LG] 14 Jun 2021  \nAntonio Emanuele Cinà  \nUniversity of Venice Venice, Italy  \n[antonioemanuele.cina@unive.it](antonioemanuele.cina@unive.it)  \nKathrin Grosse  \nUniversity of Cagliari Cagliari, Italy  \n[kathrin.grosse@unica.it](kathrin.grosse@unica.it)  \nSebastiano Vascon  \nUniversity of Venice Venice, Italy  \n[sebastiano.vascon@unive.it](sebastiano.vascon@unive.it)  \nAmbra Demontis  \nUniversity of Cagliari Cagliari, Italy  \n[ambra.demontis@unica.it](ambra.demontis@unica.it)  \nBattista Biggio  \nUniversity of Cagliari Cagliari, Italy  \n[battista.biggio@unica.it](battista.biggio@unica.it)  \nFabio Roli  \nUniversity of Cagliari Cagliari, Italy [roli@unica.it](roli@unica.it)  \nMarcello Pelillo  \nUniversity of Venice Venice, Italy  \n[pelillo@unive.it](pelillo@unive.it)  \nAbstract  \nBackdoor attacks inject poisoning samples during training, with the goal of enforcing a machine-learning model to output an attacker-chosen class when presented aspeciﬁc trigger at test time. Although backdoor attacks have been demonstrated ina variety of settings and against different models, the factors affecting their success are not yet well understood. In this work, we provide a unifying framework to study the process of backdoor learning under the lens of incremental learning and inﬂuence functions. We show that the success of backdoor attacks inherently depends on (i) the complexity of the learning algorithm, controlled by its hyperparameters, and (ii) the fraction of backdoor samples injected into the training set. These factors affect how fast a machine-learning model learns to correlate the presence of a backdoor trigger with the target class. Interestingly, our analysis shows that there exists a region in the hyperparameter space in which the accuracy on clean test samples is still high while backdoor attacks become ineffective, thereby suggesting novel criteria to improve existing defenses.  \n1 Introduction  \nMachine Learning (ML) has become pervasive in recent years and it is now a key component in several application domains, including self-driving cars and cyber-security. Its success is due to its ability to perform complex tasks, such as recognizing trafﬁc signs or discriminating between legitimate applications and malware, with high accuracy. To learn to perform complex tasks accurately, ML necessitates a massive amount of data. Therefore, ML systems are usually based on models pretrained or trained from scratch on data collected in the wild. The training process can thus be altered by malicious actors aiming to subvert the system's function, causing misclassiﬁcation of a group of test samples. To this end, an attacker is able to perform an attack called backdoor poisoning [1–3] . It consists of injecting poisoning samples containing a particular pattern (called trigger) into the training data, with an attacker-chosen class label, to enforce the classiﬁer to predict the attacker-chosen class whenever a sample containing that trigger is presented at test time.  \nPreprint. Under review.  \nSuch backdoor attacks have been demonstrated in a plethora of scenarios, including publicly-available pre-trained models available for download [1, 2], data collected from untrusted sources [4], and training outsourced to an untrusted third party (e.g., a cloud provider) [1, 2] . Backdoors have also successfully been implanted into a variety of models, including vision [2] and language models [5], graph neural networks [6] and reinforcement learning [7] . Despite the high success of this attack, the factors affecting it remain not yet well understood.  \nIn this work, we have analyzed the backdoor learning process to identify the main factors affecting the vulnerability of machine-learning models against this attack. For humans, the learning process is usually characterized using learning curves, a graphical representation of the relationship betwe","cbCaie1iEQNGIwM9","https://ap.wps.com/l/cbCaie1iEQNGIwM9","pdf",1707541,1,21,"English","en",105,"# Introduction\n## Backdoor poisoning and triggers\n## Backdoor learning curves\n# Experimental analysis\n## Factors affecting attack success\n## Robust regions in hyperparameter space","[{\"question\":\"What is the goal of backdoor poisoning attacks during training?\",\"answer\":\"They inject poisoning samples containing a trigger pattern and an attacker-chosen label so the model predicts the target class whenever the trigger is present at test time.\"},{\"question\":\"How does the paper explain backdoor learning success?\",\"answer\":\"It links success to (i) the learning algorithm complexity controlled by hyperparameters and (ii) the fraction of backdoor samples injected into training.\"},{\"question\":\"What does the “backdoor learning curves” framework measure?\",\"answer\":\"It models backdoor learning as incremental learning and uses how the loss on backdoor samples decreases over time; the curve slope is tied to influence functions to quantify backdoor learnability.\"}]","Backdoor Learning Curves - Explaining Backdoor Poisoning Beyond Influence Functions | PDF",1785733310,53,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"backdoor-learning-curves-explaining-backdoor-poisoning-beyond-influence-functions","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/backdoor-learning-curves-explaining-backdoor-poisoning-beyond-influence-functions/121013/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What is the goal of backdoor poisoning attacks during training?","Question",{"text":75,"@type":76},"They inject poisoning samples containing a trigger pattern and an attacker-chosen label so the model predicts the target class whenever the trigger is present at test time.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the paper explain backdoor learning success?",{"text":80,"@type":76},"It links success to (i) the learning algorithm complexity controlled by hyperparameters and (ii) the fraction of backdoor samples injected into training.",{"name":82,"@type":73,"acceptedAnswer":83},"What does the “backdoor learning curves” framework measure?",{"text":84,"@type":76},"It models backdoor learning as incremental learning and uses how the loss on backdoor samples decreases over time; the curve slope is tied to influence functions to quantify backdoor learnability.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]