Input-Aware Dynamic Backdoor Attack

被引:0
|
作者
Nguyen, Tuan Anh [1 ,2 ]
Tran, Tuan Anh [1 ,3 ]
机构
[1] VinAI Res, Hanoi, Vietnam
[2] Hanoi Univ Sci & Technol, Hanoi, Vietnam
[3] VinUniv, Hanoi, Vietnam
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In recent years, neural backdoor attack has been considered to be a potential security threat to deep learning systems. Such systems, while achieving the state-of-the-art performance on clean data, perform abnormally on inputs with predefined triggers. Current backdoor techniques, however, rely on uniform trigger patterns, which are easily detected and mitigated by current defense methods. In this work, we propose a novel backdoor attack technique in which the triggers vary from input to input. To achieve this goal, we implement an input-aware trigger generator driven by diversity loss. A novel cross-trigger test is applied to enforce trigger nonreusablity, making backdoor verification impossible. Experiments show that our method is efficient in various attack scenarios as well as multiple datasets. We further demonstrate that our backdoor can bypass the state of the art defense methods. An analysis with a famous neural network inspector again proves the stealthiness of the proposed attack. Our code is publicly available.
引用
收藏
页数:11
相关论文
共 50 条
  • [1] Input-Aware Approximate Computing
    Piri, Ali
    Saeedi, Sepide
    Barbareschi, Mario
    Deveautour, Bastien
    Di Carlo, Stefano
    O'Connor, Ian
    Savino, Alessandro
    Traiola, Marcello
    Bosio, Alberto
    PROCEEDINGS OF 2022 IEEE INTERNATIONAL CONFERENCE ON AUTOMATION, QUALITY AND TESTING, ROBOTICS (AQTR 2022), 2022, : 71 - 76
  • [2] Input-aware accuracy characterization for approximate circuits
    Piri, Ali
    Pappalardo, Salvatore
    Barone, Salvatore
    Barbareschi, Mario
    Deveautour, Bastien
    Traiola, Marcello
    O'Connor, Ian
    Bosio, Alberto
    2023 53RD ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOPS, DSN-W, 2023, : 179 - 182
  • [3] An Input-aware Factorization Machine for Sparse Prediction
    Yu, Yantao
    Wang, Zhen
    Yuan, Bo
    PROCEEDINGS OF THE TWENTY-EIGHTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2019, : 1466 - 1472
  • [4] Adaptive Input-aware Compilation for Graphics Engines
    Samadi, Mehrzad
    Hormati, Amir
    Mehrara, Mojtaba
    Lee, Janghaeng
    Mahlke, Scott
    ACM SIGPLAN NOTICES, 2012, 47 (06) : 13 - 22
  • [5] Input-Aware Dynamic Timestep Spiking Neural Networks for Efficient In-Memory Computing
    Li, Yuhang
    Moitra, Ahhishek
    Geller, Tamar
    Panda, Priyadarshini
    2023 60TH ACM/IEEE DESIGN AUTOMATION CONFERENCE, DAC, 2023,
  • [6] MIPAC: Dynamic Input-Aware Accuracy Control for Dynamic Auto-Tuning of Iterative Approximate Computing
    Kemp, Taylor
    Yao, Yao
    Kim, Younghyun
    2021 26TH ASIA AND SOUTH PACIFIC DESIGN AUTOMATION CONFERENCE (ASP-DAC), 2021, : 248 - 253
  • [7] A Dual Input-aware Factorization Machine for CTR Prediction
    Lu, Wantong
    Yu, Yantao
    Chang, Yongzhe
    Wang, Zhen
    Li, Chenhui
    Yuan, Bo
    PROCEEDINGS OF THE TWENTY-NINTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2020, : 3139 - 3145
  • [8] Backdoor Attack with Imperceptible Input and Latent Modification
    Khoa Doan
    Lao, Yingjie
    Li, Ping
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021, 34
  • [9] Dyn-Backdoor: Backdoor Attack on Dynamic Link Prediction
    Chen, Jinyin
    Xiong, Haiyang
    Zheng, Haibin
    Zhang, Jian
    Liu, Yi
    IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2024, 11 (01): : 525 - 542
  • [10] Graph Contrastive Representation Learning with Input-Aware and Cluster-Aware Regularization
    Li, Jin
    Li, Bingshi
    Zhang, Qirong
    Chen, Xinlong
    Huang, Xinyang
    Guo, Longkun
    Fu, Yang-Geng
    MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES: RESEARCH TRACK, ECML PKDD 2023, PT II, 2023, 14170 : 666 - 682