揭示多模态对比学习中的后门攻击漏洞及防御挑战
Backdoor Attacks on Multi-modal Contrastive Learning
- 分析对比学习在多模态场景下的后门攻击机制
- 指出对抗者可通过篡改预训练数据植入隐蔽恶意行为
- 适合关注AI安全与分布式系统可信性的研究者
对比学习已成为视觉、多模态、图结构及联邦学习等领域主流的自监督表征学习方法。然而,近期研究发现对比学习易受后门攻击和数据投毒攻击影响。攻击者可通过操纵预训练数据或模型更新,植入隐藏的恶意行为。本文对对比学习中的后门攻击进行系统性综述,分析威胁模型、攻击方法、目标领域及现有防御手段。总结该领域最新进展,强调对比学习固有的特定脆弱性,并探讨面临的挑战与未来研究方向。研究结果对工业与分布式环境中系统的安全部署具有重要启示。
原文摘要 · Abstract (English)
Contrastive learning has become a leading self- supervised approach to representation learning across domains, including vision, multimodal settings, graphs, and federated learning. However, recent studies have shown that contrastive learning is susceptible to backdoor and data poisoning attacks. In these attacks, adversaries can manipulate pretraining data or model updates to insert hidden malicious behavior. This paper offers a thorough and comparative review of backdoor attacks in contrastive learning. It analyzes threat models, attack methods, target domains, and available defenses. We summarize recent advancements in this area, underline the specific vulnerabilities inherent to contrastive learning, and discuss the challenges and future research directions. Our findings have significant implications for the secure deployment of systems in industrial and distributed environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。