arXiv:2411.03022cs.CRcs.AI2024-11被引 5

首次实现基于真实环境的脉冲神经网络后门攻击,触发隐蔽且高效。

Flashy Backdoor: Real-world Environment Backdoor Attack on SNNs with DVS Cameras

  • 提出三种新型物理环境后门攻击方法:帧式、频闪与闪光攻击
  • 攻击成功率最高达100%,同时保持高正常准确率
  • 现有防御手段在强攻击下失效或严重损害模型性能

尽管传统深度神经网络的安全漏洞已得到广泛研究,但脉冲神经网络(SNNs)对对抗攻击的脆弱性仍鲜有探索。现有后门攻击多限于数字场景,本文首次评估了真实环境中SNNs的后门攻击可行性。我们分析了现有数字攻击在物理环境中的局限性,并提出三种新攻击方法:Framed、Strobing 和 Flashy Backdoor。同时测试了剪枝、微调和微剪枝等传统防御策略在SNN上的效果,发现其虽可缓解部分攻击,却常在面对如Flashy Backdoor等强攻击时失效,或牺牲过多干净样本准确率,导致模型不可用。实验表明,所有方法在各测试数据集上均能实现最高100%的攻击成功率,且保持高清洁准确率。通过常用指标评估触发器隐蔽性,结果表明其高度隐蔽。因此,本文提出更适合检测中毒样本的新方法。研究警示需进一步加强SNN系统在真实场景下的安全防护。代码、实验与结果已在仓库公开。

原文摘要 · Abstract (English)

While security vulnerabilities in traditional Deep Neural Networks (DNNs) have been extensively studied, the susceptibility of Spiking Neural Networks (SNNs) to adversarial attacks remains mostly underexplored. Until now, the mechanisms to inject backdoors into SNN models have been limited to digital scenarios; thus, we present the first evaluation of backdoor attacks in real-world environments. We begin by assessing the applicability of existing digital backdoor attacks and identifying their limitations for deployment in physical environments. To address each of the found limitations, we present three novel backdoor attack methods on SNNs, i.e., Framed, Strobing, and Flashy Backdoor. We also assess the effectiveness of traditional backdoor procedures and defenses adapted for SNNs, such as pruning, fine-tuning, and fine-pruning. The results show that while these procedures and defenses can mitigate some attacks, they often fail against stronger methods like Flashy Backdoor or sacrifice too much clean accuracy, rendering the models unusable. Overall, all our methods can achieve up to a 100% Attack Success Rate while maintaining high clean accuracy in every tested dataset. Additionally, we evaluate the stealthiness of the triggers with commonly used metrics, finding them highly stealthy. Thus, we propose new alternatives more suited for identifying poisoned samples in these scenarios. Our results show that further research is needed to ensure the security of SNN-based systems against backdoor attacks and their safe application in real-world scenarios. The code, experiments, and results are available in our repository.

脉冲神经网络后门攻击物理安全隐蔽触发

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。