arXiv:2410.12955cs.CRcs.AI2024-10被引 1

针对长尾数据集设计动态增强攻击,提升后门攻击隐蔽性与成功率。

Long-Tailed Backdoor Attack Using Dynamic Data Augmentation Operations

  • 根据类别、样本类型和特征动态选择数据增强操作,实现自适应攻击。
  • 在长尾数据集上实现超过90%的攻击成功率,同时保持95%以上干净准确率。
  • 适用于研究模型安全的学者,尤其关注真实数据分布下的后门威胁。

近年来,后门攻击已成为深度神经网络日益严重的安全威胁,引起研究人员广泛关注。此类攻击利用第三方预训练模型在训练阶段的漏洞,使模型对正常样本表现正常,而对携带特定触发器的样本产生错误预测。现有后门攻击主要针对平衡数据集,但现实世界数据集通常呈现长尾分布。本文首次探索在此类数据集上的后门攻击。我们首先分析数据不平衡对后门攻击的影响,基于此提出一种名为动态数据增强操作(D²AO)的有效攻击方法。D²AO设计了选择器,依据类别、样本类型(干净或带毒)及样本特征动态选择增强操作;同时开发触发器生成器,生成样本特异性触发器。通过联合优化带毒模型与触发器生成器,并由动态增强选择器引导,实现了显著性能提升。大量实验表明,该方法在保持高干净准确率的同时,达到当前最优攻击效果。

原文摘要 · Abstract (English)

Recently, backdoor attack has become an increasing security threat to deep neural networks and drawn the attention of researchers. Backdoor attacks exploit vulnerabilities in third-party pretrained models during the training phase, enabling them to behave normally for clean samples and mispredict for samples with specific triggers. Existing backdoor attacks mainly focus on balanced datasets. However, real-world datasets often follow long-tailed distributions. In this paper, for the first time, we explore backdoor attack on such datasets. Specifically, we first analyze the influence of data imbalance on backdoor attack. Based on our analysis, we propose an effective backdoor attack named Dynamic Data Augmentation Operation (D$^2$AO). We design D$^2$AO selectors to select operations depending jointly on the class, sample type (clean vs. backdoored) and sample features. Meanwhile, we develop a trigger generator to generate sample-specific triggers. Through simultaneous optimization of the backdoored model and trigger generator, guided by dynamic data augmentation operation selectors, we achieve significant advancements. Extensive experiments demonstrate that our method can achieve the state-of-the-art attack performance while preserving the clean accuracy.

后门攻击长尾分布动态增强模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。