Poison Ink: Robust and Invisible Backdoor Attack
arXiv:2108.02488 · doi:10.1109/TIP.2022.3201472
Abstract
Recent research shows deep neural networks are vulnerable to different types of attacks, such as adversarial attack, data poisoning attack and backdoor attack. Among them, backdoor attack is the most cunning one and can occur in almost every stage of deep learning pipeline. Therefore, backdoor attack has attracted lots of interests from both academia and industry. However, most existing backdoor attack methods are either visible or fragile to some effortless pre-processing such as common data transformations. To address these limitations, we propose a robust and invisible backdoor attack called "Poison Ink". Concretely, we first leverage the image structures as target poisoning areas, and fill them with poison ink (information) to generate the trigger pattern. As the image structure can keep its semantic meaning during the data transformation, such trigger pattern is inherently robust to data transformations. Then we leverage a deep injection network to embed such trigger pattern into the cover image to achieve stealthiness. Compared to existing popular backdoor attack methods, Poison Ink outperforms both in stealthiness and robustness. Through extensive experiments, we demonstrate Poison Ink is not only general to different datasets and network architectures, but also flexible for different attack scenarios. Besides, it also has very strong resistance against many state-of-the-art defense techniques.
IEEE Transactions on Image Processing (TIP)
References in corpus (10)
- Very Deep Convolutional Networks for Large-Scale Image Recognition
- Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning
- On Evaluating Adversarial Robustness
- Backdoor Attacks and Countermeasures on Deep Learning: A Comprehensive Review
- WaNet -- Imperceptible Warping-based Backdoor Attack
- Defending Neural Backdoors via Generative Distribution Modeling
- Practical Detection of Trojan Neural Networks: Data-Limited and Data-Free Cases
- Backdoor Attack through Frequency Domain
- What Doesn't Kill You Makes You Robust(er): How to Adversarially Train against Data Poisoning
- Exploring Structure Consistency for Deep Model Watermarking
Cited by in corpus (10)
- GIF: A General Graph Unlearning Strategy via Influence Function
- BadCM: Invisible Backdoor Attack Against Cross-Modal Learning
- Compression-Resistant Backdoor Attack against Deep Neural Networks
- Sneaky Spikes: Uncovering Stealthy Backdoor Attacks in Spiking Neural Networks with Neuromorphic Data
- M-to-N Backdoor Paradigm: A Multi-Trigger and Multi-Target Attack to Deep Learning Models
- Fake the Real: Backdoor Attack on Deep Speech Classification via Voice Conversion
- A General Framework for Defending Against Backdoor Attacks via Influence Graph
- Sample-Independent Federated Learning Backdoor Attack in Speaker Recognition
- Hypnopaedia-Aware Machine Unlearning via Psychometrics of Artificial Mental Imagery
- Imitation Game for Adversarial Disillusion with Chain-of-Thought Reasoning in Generative AI