Return
HashRuler: Lightweight Detection of Anomalous Hash Codes for Backdoor Defense
W
L
A
DOI:10.1109/tifs.2026.3714145.png)
Abstract
En 中文
Deep hashing is widely adopted in large-scale image retrieval for its efficiency, but its reliance on large-scale datasets makes it vulnerable to backdoor threats. Recently, BadHash, a clean-label backdoor attack, has shown the ability to compromise deep hashing models by generating poisoned samples via a conditional generative adversarial network. These samples appear benign but are crafted to manipulate hash codes, making existing defense methods ineffective in the hash space. To address the challenge, we propose HashRuler, a lightweight and effective hash-code-based detection framework tailored for deep hashing models. HashRuler introduces two complementary metrics, Center Similarity Deviation (CSD) and Local Sparsity (LS), which jointly capture global and local distributional anomalies of sample hash codes. CSD quantifies a sample’s deviation from the class-specific hash center, while LS measures local outlier behavior relative to its nearest neighbors. Experimental results show that HashRuler achieves up to 97% detection accuracy against BadHash attacks, with extensive evaluations across diverse datasets, attack types, and model architectures confirming its effectiveness and generalizability.
Keywords:
Backdoor defense
deep learning
image retrieval
hash code
Journal
IF:
8
Papers:
5.2K
Citations:
2.3W
