arXiv:2502.10490cs.CRcs.AI2025-02

提出一种抗干扰的图像后门攻击,可抵御旋转裁剪等现实变化。

A Robust Attack: Displacement Backdoor Attack

  • 通过位移目标样本并自融合生成后门样本。
  • 在旋转、裁剪等数据增强下仍保持超90%攻击成功率。
  • 适合研究防御机制或评估模型鲁棒性的研究人员。

随着人工智能在生活中的广泛应用,其带来的便利背后也潜藏数据污染和对抗攻击等隐患,尤其在自动驾驶、医疗等实时应用中可能造成严重后果。其中,后门攻击因隐蔽性强、部署简单而备受关注,但现有方法在实际应用中常受抖动、亮度变化等因素影响,效果不佳。为此,本文提出一种高鲁棒性后门攻击——位移后门攻击(Displacement Backdoor Attack, DBA),通过将目标样本进行位移并与其自身融合生成后门样本。实验表明,该攻击能有效抵抗模拟真实场景差异的数据增强,如旋转、裁剪等,在多种条件下均保持超过90%的攻击成功率。

原文摘要 · Abstract (English)

As artificial intelligence becomes more prevalent in our lives, people are enjoying the convenience it brings, but they are also facing hidden threats, such as data poisoning and adversarial attacks. These threats can have disastrous consequences for the application of artificial intelligence, especially for some applications that take effect immediately, such as autonomous driving and medical fields. Among these threats, backdoor attacks have left a deep impression on people with their concealment and simple deployment, making them a threat that cannot be ignored, however, in the process of deploying the backdoor model, the backdoor attack often has some reasons that make it unsatisfactory in real-world applications, such as jitter and brightness changes. Based on this, we propose a highly robust backdoor attack that shifts the target sample and combines it with itself to form a backdoor sample, the Displacement Backdoor Attack(DBA). Experimental results show that the DBA attack can resist data augmentation that simulates real-world differences, such as rotation and cropping.

后门攻击图像安全鲁棒性对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。