Class-Conditional Neural Polarizer: A Lightweight and Effective Backdoor Defense by Purifying Poisoned Features
arXiv preprint, 2025
Abstract
This work extends neural-polarizer defenses by conditioning purification on class information. Its replicated, embedded, and attention-based variants reduce reliance on accurate target-label estimation while preserving the lightweight character of the original approach.
Citation
Zhu, Mingli, Shaokui Wei, Hongyuan Zha, and Baoyuan Wu. "Class-Conditional Neural Polarizer: A Lightweight and Effective Backdoor Defense by Purifying Poisoned Features." arXiv:2502.18520, 2025.
