Rethinking the Trigger of Backdoor Attack
arXiv:2004.04692
Abstract
Backdoor attack intends to inject hidden backdoor into the deep neural networks (DNNs), such that the prediction of the infected model will be maliciously changed if the hidden backdoor is activated by the attacker-defined trigger, while it performs well on benign samples. Currently, most of existing backdoor attacks adopted the setting of \emph{static} trigger, triggers across the training and testing images follow the same appearance and are located in the same area. In this paper, we revisit this attack paradigm by analyzing the characteristics of the static trigger. We demonstrate that such an attack paradigm is vulnerable when the trigger in testing images is not consistent with the one used for training. We further explore how to utilize this property for backdoor defense, and discuss how to alleviate such vulnerability of existing attacks.
18 pages
References in corpus (11)
- Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning
- Poisoning Attacks against Support Vector Machines
- Backdoor Attacks and Countermeasures on Deep Learning: A Comprehensive Review
- On the Effectiveness of Mitigating Data Poisoning Attacks with Gradient Shaping
- Defending Neural Backdoors via Generative Distribution Modeling
- Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning Attacks
- Weight Poisoning Attacks on Pre-trained Models
- Label-Consistent Backdoor Attacks
- Bridging Mode Connectivity in Loss Landscapes and Adversarial Robustness
- A Unified Framework for Data Poisoning Attack to Graph-based Semi-supervised Learning
- ConFoc: Content-Focus Protection Against Trojan Attacks on Neural Networks
Cited by in corpus (16)
- Wild Patterns Reloaded: A Survey of Machine Learning Security against Training Data Poisoning
- Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural Networks
- Backdoor Attacks and Countermeasures on Deep Learning: A Comprehensive Review
- Poison Ink: Robust and Invisible Backdoor Attack
- Reflection Backdoor: A Natural Backdoor Attack on Deep Neural Networks
- Robust Backdoor Attacks against Deep Neural Networks in Real Physical World
- DeepSweep: An Evaluation Framework for Mitigating DNN Backdoor Attacks using Data Augmentation
- Poisoned classifiers are not only backdoored, they are fundamentally broken
- Open-sourced Dataset Protection via Backdoor Watermarking
- Be Careful about Poisoned Word Embeddings: Exploring the Vulnerability of the Embedding Layers in NLP Models
- Defending Against Backdoor Attacks in Natural Language Generation
- EX-RAY: Distinguishing Injected Backdoor from Natural Features in Neural Networks by Examining Differential Feature Symmetry
- Towards Practical Deployment-Stage Backdoor Attack on Deep Neural Networks
- Backdoor Attacks on Pre-trained Models by Layerwise Weight Poisoning
- RAP: Robustness-Aware Perturbations for Defending against Backdoor Attacks on NLP Models
- Backdoor Attack against Speaker Verification