Skip to content

About

Core implementation of EVO-Detect for dynamic MLLM backdoor detection

Resources

Stars

2 stars

Watchers

0 watching

Forks

Latest commit

 

History

1 Commit

Folders and files

Repository files navigation

EVO-Detect

Core implementation of EVO-Detect, the dual-flow backdoor detection method described in Beyond Static Cues: Unified Dynamic Detection of MLLM Backdoors via Dual-Flow Trajectory Analysis.

This repository intentionally contains only the online method implementation:

  • Attention Flow extraction over early decoding steps;
  • Logits Flow extraction with full, text-only, and image-only inputs;
  • trajectory aggregation and sample feature construction;
  • control-aware calibration, scoring, and thresholding.

Dataset preparation, poisoning, training, benchmark adapters, model-specific data loaders, baselines, plotting, experiment orchestration, and paper results are intentionally excluded. This is a compact core-code release, not a full artifact for reproducing every table in the paper.

Installation

pip install -r requirements.txt
pip install -e . --no-deps

The implementation is extracted from the project's online evaluation code and retains its original behavior. It supports the model-loading paths present in that implementation, including Qwen-VL-style and InternVL-style Hugging Face checkpoints. No additional compatibility layer is provided.

Package layout

src/evo_detect/
├── flows.py       # model loading and Attention/Logits Flow extraction
├── scoring.py     # calibration, scoring, and decision utilities
└── __init__.py    # public API

Core API

evo_detect.flows exposes:

  • load_model
  • extract_attention_flow
  • extract_logits_flow
  • generate_output
  • aggregate_flows
  • build_sample_feature

evo_detect.scoring exposes the reference trajectory, metric, calibration, dual-trigger scoring, and threshold utilities used by the online pipeline.

The default early-decoding horizon in the paper is five tokens; callers pass that horizon through max_new_tokens when extracting each flow.

Scope

The caller is responsible for loading samples and images, supplying clean reference and matched-control groups, and persisting any scores or filtered datasets. The implementation does not inspect dataset labels or impose a JSON schema.

License

MIT. See LICENSE.

About

Core implementation of EVO-Detect for dynamic MLLM backdoor detection

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages