arXiv:2501.07192cs.CRcs.CV2025-01

用多种小触发器组合攻击,隐蔽性更强且能绕过现有防御

A4O: All Trigger for One sample

  • 将多种小幅度触发器组合使用,降低单个触发器的可检测性
  • 在三个数据集上实现高攻击成功率,同时绕过主流防御方法
  • 适合研究后门攻击与防御机制的学者,以及安全评估人员

后门攻击已成为深度神经网络的重大威胁,但现有研究多采用单一类型的触发器。由此导致的防御方法通常假设触发器具有统一表现形式,这带来了漏洞。本文提出一种新型后门攻击机制,融合多种触发器类型,兼顾隐蔽性与有效性。我们观察到:触发器的大小与其攻击性能、可检测性和可移除性呈正相关。基于此,我们减小每种触发器的幅度,并通过组合实现强攻击效果,同时保持整体信号低于防御系统的检测阈值。在三个标准数据集上的大量实验表明,该方法能实现高攻击成功率(ASR),并持续绕过当前最先进的防御方案。

原文摘要 · Abstract (English)

Backdoor attacks have become a critical threat to deep neural networks (DNNs), drawing many research interests. However, most of the studied attacks employ a single type of trigger. Consequently, proposed backdoor defenders often rely on the assumption that triggers would appear in a unified way. In this paper, we show that this naive assumption can create a loophole, allowing more sophisticated backdoor attacks to bypass. We design a novel backdoor attack mechanism that incorporates multiple types of backdoor triggers, focusing on stealthiness and effectiveness. Our journey begins with the intriguing observation that the performance of a backdoor attack in deep learning models, as well as its detectability and removability, are all proportional to the magnitude of the trigger. Based on this correlation, we propose reducing the magnitude of each trigger type and combining them to achieve a strong backdoor relying on the combined trigger while still staying safely under the radar of defenders. Extensive experiments on three standard datasets demonstrate that our method can achieve high attack success rates (ASRs) while consistently bypassing state-of-the-art defenses.

后门攻击模型安全隐蔽性防御绕过

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。