arXiv:2511.14074cs.CRcs.LG2025-11被引 11

提出动态触发生成技术,对物联网传感数据实施隐蔽后门攻击

Dynamic Black-box Backdoor Attacks on IoT Sensory Data

  • 设计动态触发机制,在传感器数据中注入隐蔽攻击信号
  • 仅需微小扰动即可在多个数据集和模型上成功触发后门
  • 适合研究物联网安全与对抗攻击的学者及工程师

基于传感器数据的识别系统广泛应用于步态认证和人体活动识别(HAR)等场景。现代可穿戴与智能设备内置多种惯性测量单元(IMU)传感器,其采集的数据可输入机器学习模型进行人类活动训练与分类。尽管深度学习模型在活动识别方面表现优异,但存在诸多安全风险。本文提出一种新型动态触发生成技术,用于对基于传感器数据的物联网系统实施黑盒对抗攻击。实证分析表明,该攻击在多个数据集和分类器模型上均有效,且对输入数据的扰动极小。我们还对比了不同中毒技术在性能与隐蔽性方面的表现,并探讨了几种对抗防御机制对该触发生成技术效果的影响。

原文摘要 · Abstract (English)

Sensor data-based recognition systems are widely used in various applications, such as gait-based authentication and human activity recognition (HAR). Modern wearable and smart devices feature various built-in Inertial Measurement Unit (IMU) sensors, and such sensor-based measurements can be fed to a machine learning-based model to train and classify human activities. While deep learning-based models have proven successful in classifying human activity and gestures, they pose various security risks. In our paper, we discuss a novel dynamic trigger-generation technique for performing black-box adversarial attacks on sensor data-based IoT systems. Our empirical analysis shows that the attack is successful on various datasets and classifier models with minimal perturbation on the input data. We also provide a detailed comparative analysis of performance and stealthiness to various other poisoning techniques found in backdoor attacks. We also discuss some adversarial defense mechanisms and their impact on the effectiveness of our trigger-generation technique.

后门攻击物联网安全传感器数据对抗样本

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。