Stealthy Frequency-Domain Backdoor Attacks: Fourier Decomposition and Fundamental Frequency Injection

被引:2
|
作者
Ma, Qianli [1 ]
Qin, Junping [1 ]
Yan, Kai [1 ]
Wang, Lei [1 ]
Sun, Hao [1 ]
机构
[1] Inner Mongolia Univ Technol, Coll Data Sci & Applicat, Hohhot 010000, Peoples R China
关键词
AI security; backdoor attacks; deep learning; Fourier decomposition;
D O I
10.1109/LSP.2023.3330126
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The rising reliance on deep learning models that are black-box in nature is concerning stakeholders about their security in artificial intelligence (AI) applications. Backdoor attacks are a significant challenge due to their ability to remain undetectable. Currently, researchers are focusing on the injection of frequency-domain triggers to enhance the covert nature of these attacks. Nevertheless, this method can introduce uncertain frequency variations that reduce the effectiveness of the attacks. We propose a method for Frequency-Domain Backdoor Attacks in response. The method utilizes Fourier Decomposition and Fundamental Frequency Injection techniques. In our method, we employ Fourier decomposition to mask the fundamental frequency of unsuitable bands, thereby guaranteeing covert trigger injection. As a result, this technique enhances temporal and spectral camouflaging, considerably reducing the likelihood of discovery. Our research contributes to a deeper understanding of backdoor attacks and enhances the security of AI systems by examining this innovative approach. Our approach to AI security centres around exploiting the smooth characteristics of frequencies within the frequency domain. This approach forms the foundation of our work in the field of artificial intelligence security.
引用
收藏
页码:1677 / 1681
页数:5
相关论文
共 50 条
  • [21] FREQUENCY-DOMAIN INTERPOLATION
    LEONDES, CT
    RIVERS, DD
    IEEE TRANSACTIONS ON AEROSPACE AND ELECTRONIC SYSTEMS, 1977, 13 (03) : 323 - 326
  • [22] DECONVOLUTION IN THE FREQUENCY-DOMAIN
    FRIESEN, WI
    MICHAELIAN, KH
    APPLIED SPECTROSCOPY, 1985, 39 (03) : 484 - 490
  • [23] An Improved Traffic Matrix Decomposition Method with Frequency-Domain Regularization
    Wang, Zhe
    Hu, Kai
    Yin, Baolin
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2013, E96D (03): : 731 - 734
  • [24] Frequency-Domain Modeling and Analysis of Injection-Locked Oscillators
    Zheng, Xuqiang
    Lv, Fangxu
    Zhou, Lei
    Wu, Danyu
    Wu, Jin
    Zhang, Chun
    Rhee, Woogeun
    Liu, Xinyu
    IEEE JOURNAL OF SOLID-STATE CIRCUITS, 2020, 55 (06) : 1651 - 1664
  • [25] Single-Carrier Frequency-Domain Equalization Based on Frequency-Domain Oversampling
    Zhang, Xiaohui
    Chen, Enqing
    Mu, Xiaomin
    IEEE COMMUNICATIONS LETTERS, 2012, 16 (01) : 24 - 26
  • [26] High order HDG method and domain decomposition solvers for frequency-domain electromagnetics
    Agullo, Emmanuel
    Giraud, Luc
    Gobe, Alexis
    Kuhn, Matthieu
    Lanteri, Stephane
    Moya, Ludovic
    INTERNATIONAL JOURNAL OF NUMERICAL MODELLING-ELECTRONIC NETWORKS DEVICES AND FIELDS, 2020, 33 (02)
  • [27] Domain decomposition based on the spectral element method for frequency-domain computational elastodynamics
    Linlin SHI
    Mingwei ZHUANG
    Yuanguo ZHOU
    Na LIU
    Qinghuo LIU
    ScienceChina(EarthSciences), 2021, 64 (03) : 388 - 403
  • [28] Domain decomposition based on the spectral element method for frequency-domain computational elastodynamics
    Linlin Shi
    Mingwei Zhuang
    Yuanguo Zhou
    Na Liu
    Qinghuo Liu
    Science China Earth Sciences, 2021, 64 : 388 - 403
  • [29] Domain decomposition based on the spectral element method for frequency-domain computational elastodynamics
    Shi, Linlin
    Zhuang, Mingwei
    Zhou, Yuanguo
    Liu, Na
    Liu, Qinghuo
    SCIENCE CHINA-EARTH SCIENCES, 2021, 64 (03) : 388 - 403
  • [30] CONSTRAINED FREQUENCY-DOMAIN ALGORITHMS FOR DETERMINATION OF PARAMETERS OF FUNDAMENTAL SINEWAVE OF SIGNALS
    EICHHORN, KF
    LOBOS, T
    RUCZEWSKI, P
    IEE PROCEEDINGS-C GENERATION TRANSMISSION AND DISTRIBUTION, 1993, 140 (06) : 477 - 480