Input-Aware Dynamic Backdoor Attack

被引:0
|
作者
Nguyen, Tuan Anh [1 ,2 ]
Tran, Tuan Anh [1 ,3 ]
机构
[1] VinAI Res, Hanoi, Vietnam
[2] Hanoi Univ Sci & Technol, Hanoi, Vietnam
[3] VinUniv, Hanoi, Vietnam
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In recent years, neural backdoor attack has been considered to be a potential security threat to deep learning systems. Such systems, while achieving the state-of-the-art performance on clean data, perform abnormally on inputs with predefined triggers. Current backdoor techniques, however, rely on uniform trigger patterns, which are easily detected and mitigated by current defense methods. In this work, we propose a novel backdoor attack technique in which the triggers vary from input to input. To achieve this goal, we implement an input-aware trigger generator driven by diversity loss. A novel cross-trigger test is applied to enforce trigger nonreusablity, making backdoor verification impossible. Experiments show that our method is efficient in various attack scenarios as well as multiple datasets. We further demonstrate that our backdoor can bypass the state of the art defense methods. An analysis with a famous neural network inspector again proves the stealthiness of the proposed attack. Our code is publicly available.
引用
收藏
页数:11
相关论文
共 50 条
  • [41] Invisible Backdoor Attack With Dynamic Triggers Against Person Re-Identification
    Sun, Wenli
    Jiang, Xinyang
    Dou, Shuguang
    Li, Dongsheng
    Miao, Duoqian
    Deng, Cheng
    Zhao, Cairong
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 307 - 319
  • [42] Coupling of state space modules and attention mechanisms: An input-aware multi-contrast MRI synthesis method
    Chen, Shuai
    Zhang, Ruoyu
    Liang, Huazheng
    Qian, Yunzhu
    Zhou, Xuefeng
    MEDICAL PHYSICS, 2025, 52 (04) : 2269 - 2278
  • [43] Classification of Giemsa staining chromosome using input-aware deep convolutional neural network with integrated uncertainty estimates
    Wei, Hua
    Gao, Wen
    Nie, Haitao
    Sun, Jiaqi
    Zhu, Ming
    BIOMEDICAL SIGNAL PROCESSING AND CONTROL, 2022, 71
  • [44] STEALTHY BACKDOOR ATTACK WITH ADVERSARIAL TRAINING
    Feng, Le
    Li, Sheng
    Qian, Zhenxing
    Zhang, Xinpeng
    2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 2969 - 2973
  • [45] Survey of Textual Backdoor Attack and Defense
    Zheng M.
    Lin Z.
    Liu Z.
    Fu P.
    Wang W.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2024, 61 (01): : 221 - 242
  • [46] Backdoor Attack With Sparse and Invisible Trigger
    Gao, Yinghua
    Li, Yiming
    Gong, Xueluan
    Li, Zhifeng
    Xia, Shu-Tao
    Wang, Qian
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 6364 - 6376
  • [47] Sniper Backdoor: Single Client Targeted Backdoor Attack in Federated Learning
    Abad, Gorka
    Paguada, Servio
    Ersoy, Oguzhan
    Picek, Stjepan
    Ramirez-Duran, Victor Julio
    Urbieta, Aitor
    2023 IEEE CONFERENCE ON SECURE AND TRUSTWORTHY MACHINE LEARNING, SATML, 2023, : 377 - 391
  • [48] Data Poisoning Quantization Backdoor Attack
    Tran Huynh
    Anh Tran
    Khoa D Doan
    Tung Pham
    COMPUTER VISION - ECCV 2024, PT LXXXIV, 2025, 15142 : 38 - 54
  • [49] Stealthy Backdoor Attack for Code Models
    Yang, Zhou
    Xu, Bowen
    Zhang, Jie M.
    Kang, Hong Jin
    Shi, Jieke
    He, Junda
    Lo, David
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2024, 50 (04) : 721 - 741
  • [50] IA-SpGEMM An Input-aware Auto-tuning Framework for Parallel Sparse Matrix-Matrix Multiplication
    Xie, Zhen
    Tan, Guangming
    Liu, Weifeng
    Sun, Ninghui
    INTERNATIONAL CONFERENCE ON SUPERCOMPUTING (ICS 2019), 2019, : 94 - 105