arXiv:2501.01263cs.CRcs.AI2025-01被引 2

用隐写术生成隐蔽触发器,实现对安卓应用中真实模型的高效后门攻击。

Stealthy Backdoor Attack to Real-world Models in Android Apps

  • 利用深度神经网络隐写术生成难以察觉的样本特定触发器。
  • 在89个真实模型上实现12.5%更高的攻击成功率,同时保持模型正常性能。
  • 适合研究移动设备安全、后门攻击防御的开发者与安全研究人员。

深度神经网络(DNN)因其卓越性能被广泛应用于各类场景,许多深度学习(DL)模型已嵌入移动端应用,通过设备端推理提升用户体验。然而,将DL模型部署于用户手机也带来诸多安全威胁,其中后门攻击尤为突出。尽管已有大量研究探讨后门攻击方法,但针对真实世界部署模型的研究仍较少,且普遍存在有效性和隐蔽性不足的问题。本文提出一种基于隐写术的新型后门攻击方法,利用不可感知且依赖样本的触发器,增强对真实世界模型的攻击效果。实验验证了该方法在四种先进DNN模型上的有效性;系统评估了其隐蔽性,确保攻击难以察觉。进一步,在收集的38,387个安卓应用中提取出89个实际部署的模型,进行攻击测试。结果表明,相比DeepPayload等基线方法,本方法平均攻击成功率提升12.50%,同时更好维持模型正常功能。大量实验显示,该方法在真实场景下具备更强的有效性、鲁棒性与隐蔽性。

原文摘要 · Abstract (English)

Powered by their superior performance, deep neural networks (DNNs) have found widespread applications across various domains. Many deep learning (DL) models are now embedded in mobile apps, making them more accessible to end users through on-device DL. However, deploying on-device DL to users' smartphones simultaneously introduces several security threats. One primary threat is backdoor attacks. Extensive research has explored backdoor attacks for several years and has proposed numerous attack approaches. However, few studies have investigated backdoor attacks on DL models deployed in the real world, or they have shown obvious deficiencies in effectiveness and stealthiness. In this work, we explore more effective and stealthy backdoor attacks on real-world DL models extracted from mobile apps. Our main justification is that imperceptible and sample-specific backdoor triggers generated by DNN-based steganography can enhance the efficacy of backdoor attacks on real-world models. We first confirm the effectiveness of steganography-based backdoor attacks on four state-of-the-art DNN models. Subsequently, we systematically evaluate and analyze the stealthiness of the attacks to ensure they are difficult to perceive. Finally, we implement the backdoor attacks on real-world models and compare our approach with three baseline methods. We collect 38,387 mobile apps, extract 89 DL models from them, and analyze these models to obtain the prerequisite model information for the attacks. After identifying the target models, our approach achieves an average of 12.50% higher attack success rate than DeepPayload while better maintaining the normal performance of the models. Extensive experimental results demonstrate that our method enables more effective, robust, and stealthy backdoor attacks on real-world models.

后门攻击移动安全隐写术模型劫持

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。