通过频域嵌入触发器,实现对图像压缩模型的多类型鲁棒后门攻击。
Robust and Transferable Backdoor Attacks Against Deep Image Compression With Selective Frequency Prior
- 在DCT域设计频域触发器,适配压缩模型特性。
- 支持比特率下降与识别任务失效,攻击效果显著。
- 具备跨模型迁移能力,适合研究安全漏洞者参考。
基于深度学习的图像压缩技术已超越传统方法,但深度神经网络仍易受后门攻击影响,即预设触发器可诱导恶意行为。本文提出一种新型频域触发注入模型,针对学习型图像压缩模型发起多触发后门攻击。受压缩编码中广泛使用的DCT启发,触发器被嵌入DCT域。设计了适应不同场景的攻击目标:1)降低压缩质量(以比特率和重建精度衡量);2)针对人脸识别、语义分割等任务驱动指标实施破坏。为提升训练效率,提出动态损失函数,在减少超参数依赖的同时有效优化攻击目标。针对高级防御场景,评估攻击对预处理防御的抗性,并提出两阶段训练策略,结合鲁棒频率选择增强攻击韧性。为进一步提升跨模型与跨领域迁移能力,训练中调整攻击损失中的分类边界。实验表明,仅需微调编码器参数,即可在同一压缩模型中成功注入多个后门及其触发器,展现出强大性能与通用性。
原文摘要 · Abstract (English)
Recent advancements in deep learning-based compression techniques have surpassed traditional methods. However, deep neural networks remain vulnerable to backdoor attacks, where pre-defined triggers induce malicious behaviors. This paper introduces a novel frequency-based trigger injection model for launching backdoor attacks with multiple triggers on learned image compression models. Inspired by the widely used DCT in compression codecs, triggers are embedded in the DCT domain. We design attack objectives tailored to diverse scenarios, including: 1) degrading compression quality in terms of bit-rate and reconstruction accuracy; 2) targeting task-driven measures like face recognition and semantic segmentation. To improve training efficiency, we propose a dynamic loss function that balances loss terms with fewer hyper-parameters, optimizing attack objectives effectively. For advanced scenarios, we evaluate the attack's resistance to defensive preprocessing and propose a two-stage training schedule with robust frequency selection to enhance resilience. To improve cross-model and cross-domain transferability for downstream tasks, we adjust the classification boundary in the attack loss during training. Experiments show that our trigger injection models, combined with minor modifications to encoder parameters, successfully inject multiple backdoors and their triggers into a single compression model, demonstrating strong performance and versatility. (*Due to the notification of arXiv "The Abstract field cannot be longer than 1,920 characters", the appeared Abstract is shortened. For the full Abstract, please download the Article.)
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。