Back to Introduction
Current research

OmicsDefense

A layer-resolved framework for detecting and mitigating training-data backdoors in single-cell foundation models.

OmicsDefense attack construction, WDF detection and defense, and clean-model recovery workflow

Figure caption

OmicsDefense separates the workflow into three stages. First, a training-only backdoor attack is constructed by selecting a small set of non-target samples, applying sparse token/value changes, and rewriting their labels. Next, the same samples are compared between a frozen pretrained reference and a poisoned fine-tuned model; layer-wise representation divergence is used by the WDF detector to identify suspicious training candidates. Finally, a clean model and trusted embedding bank support KNN-based decisions to retain, relabel, or discard candidates before fresh retraining. Held-out clean and triggered data are reserved for final evaluation rather than used in the defense workflow.