优化目标类别映射,显著提升多目标后门攻击成功率。
Enhancing All-to-X Backdoor Attacks with Optimized Target Class Mapping
- 设计新策略优化后门触发器分组与目标类分配
- 在多个数据集上平均提升攻击成功率14.1%~16.4%
- 揭示多目标后门攻击的隐蔽性,适合安全研究者关注
后门攻击严重威胁机器学习系统,现有研究多集中于单目标全向一(A2O)攻击,忽视了更复杂的多目标全向多(A2X)攻击。本文首次证明A2X攻击对主流防御机制具有鲁棒性,并提出一种新攻击策略,通过优化分组与目标类分配机制,在保持鲁棒性的前提下显著提升攻击成功率:在CIFAR10、CIFAR100和Tiny-ImageNet上的平均提升分别为6.7%、16.4%和14.1%,最高提升达28%。该研究有助于提升对A2X攻击的认知,推动该领域的深入探索。代码已公开于https://github.com/kazefjj/A2X-backdoor。
原文摘要 · Abstract (English)
Backdoor attacks pose severe threats to machine learning systems, prompting extensive research in this area. However, most existing work focuses on single-target All-to-One (A2O) attacks, overlooking the more complex All-to-X (A2X) attacks with multiple target classes, which are often assumed to have low attack success rates. In this paper, we first demonstrate that A2X attacks are robust against state-of-the-art defenses. We then propose a novel attack strategy that enhances the success rate of A2X attacks while maintaining robustness by optimizing grouping and target class assignment mechanisms. Our method improves the attack success rate by up to 28%, with average improvements of 6.7%, 16.4%, 14.1% on CIFAR10, CIFAR100, and Tiny-ImageNet, respectively. We anticipate that this study will raise awareness of A2X attacks and stimulate further research in this under-explored area. Our code is available at https://github.com/kazefjj/A2X-backdoor .
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。