提出空间定位的隐形多目标后门攻击,提升隐蔽性与攻击范围。
SFIBA: Spatial-based Full-target Invisible Backdoor Attacks
- 将触发器限制在特定空间区域和形态,确保攻击目标精准。
- 在多个数据集上实现100%攻击成功率,且不降低正常样本性能。
- 适合研究后门防御机制或评估模型安全性的研究人员。
多目标后门攻击对深度神经网络构成严重威胁,可通过单个后门注入控制模型将带触发器的中毒样本误分类为任意目标类别,相比传统攻击更具优势。然而,现有方法在黑盒场景下难以保证触发器的特异性和隐蔽性,存在两大问题:一是在仅能操控训练数据时无法同时针对所有类别,影响实际攻击效果;二是触发器常具视觉可感知性,易被检测。为此,我们提出空间基全目标隐形后门攻击(SFIBA),通过将不同类别的触发器限定于像素空间中的特定局部区域和形态以确保特异性,并采用基于频域的触发器注入方法保障隐蔽性。具体而言,对每个触发器注入,先对局部空间区域的干净样本进行快速傅里叶变换获取幅值谱,再使用离散小波变换提取幅值谱特征,并通过奇异值分解整合触发器。随后,在像素空间中选择性过滤触发器部分以实现形态约束,并根据视觉效果调整注入系数。在多个数据集和模型上的实验表明,SFIBA在保持良性样本性能的同时,实现优异的攻击成功率(100%)和隐蔽性,并可绕过现有后门防御机制。
原文摘要 · Abstract (English)
Multi-target backdoor attacks pose significant security threats to deep neural networks, as they can preset multiple target classes through a single backdoor injection. This allows attackers to control the model to misclassify poisoned samples with triggers into any desired target class during inference, exhibiting superior attack performance compared with conventional backdoor attacks. However, existing multi-target backdoor attacks fail to guarantee trigger specificity and stealthiness in black-box settings, resulting in two main issues. First, they are unable to simultaneously target all classes when only training data can be manipulated, limiting their effectiveness in realistic attack scenarios. Second, the triggers often lack visual imperceptibility, making poisoned samples easy to detect. To address these problems, we propose a Spatial-based Full-target Invisible Backdoor Attack, called SFIBA. It restricts triggers for different classes to specific local spatial regions and morphologies in the pixel space to ensure specificity, while employing a frequency-domain-based trigger injection method to guarantee stealthiness. Specifically, for injection of each trigger, we first apply fast fourier transform to obtain the amplitude spectrum of clean samples in local spatial regions. Then, we employ discrete wavelet transform to extract the features from the amplitude spectrum and use singular value decomposition to integrate the trigger. Subsequently, we selectively filter parts of the trigger in pixel space to implement trigger morphology constraints and adjust injection coefficients based on visual effects. We conduct experiments on multiple datasets and models. The results demonstrate that SFIBA can achieve excellent attack performance and stealthiness, while preserving the model's performance on benign samples, and can also bypass existing backdoor defenses.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。