arXiv:2502.11687cs.CRcs.AI2025-02中稿 · 62nd Design Automa…被引 3

ReVeil利用机器遗忘实现隐蔽后门攻击,无需模型访问即可绕过检测。

ReVeil: Unconstrained Concealed Backdoor Attack on Deep Neural Networks using Machine Unlearning

  • 在训练数据收集阶段植入后门,无需模型或额外数据
  • 预部署时低攻击成功率,部署后通过机器遗忘恢复高成功率
  • 可绕过三种主流检测方法,适用于无访问权限场景

后门攻击在深度神经网络中嵌入隐藏功能,通过特定输入触发恶意行为。现有防御机制通过监测异常推理来识别攻击,但隐蔽后门可通过低预部署攻击成功率(ASR)并利用机器遗忘在部署后恢复高ASR来逃避检测。现有隐蔽后门常依赖白盒或黑盒访问、辅助数据,实用性受限。本文提出ReVeil,一种针对DNN训练流水线数据收集阶段的隐蔽后门攻击,无需模型访问或辅助数据。ReVeil在四个数据集和四种触发模式下保持低预部署ASR,成功规避三种主流后门检测方法,并通过机器遗忘在部署后恢复高ASR。

原文摘要 · Abstract (English)

Backdoor attacks embed hidden functionalities in deep neural networks (DNN), triggering malicious behavior with specific inputs. Advanced defenses monitor anomalous DNN inferences to detect such attacks. However, concealed backdoors evade detection by maintaining a low pre-deployment attack success rate (ASR) and restoring high ASR post-deployment via machine unlearning. Existing concealed backdoors are often constrained by requiring white-box or black-box access or auxiliary data, limiting their practicality when such access or data is unavailable. This paper introduces ReVeil, a concealed backdoor attack targeting the data collection phase of the DNN training pipeline, requiring no model access or auxiliary data. ReVeil maintains low pre-deployment ASR across four datasets and four trigger patterns, successfully evades three popular backdoor detection methods, and restores high ASR post-deployment through machine unlearning.

后门攻击机器遗忘隐蔽性无访问

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。