提出可动态调节触发强度的多形态后门攻击,提升语义通信系统攻击灵活性。
Toward Polymorphic Backdoor against Semantic Communication via Intensity-Based Poisoning

- 通过分级强度触发污染训练数据,实现对语义知识的精细控制。
- 在多个模型和数据集上实现高攻击成功率,同时保持正常通信质量。
- 适用于研究语义通信安全的学者,尤其关注对抗性攻击与防御者。
语义通信(SC)后门攻击利用触发器诱导系统生成预设输出,现有方法采用单一目标的单形态攻击范式,限制了攻击多样性、效率与异构场景下的适应性。为此,本文提出SemBugger,一种多形态语义通信后门攻击。通过动态调整触发强度,实现对系统语义知识的细粒度操控,生成多样恶意结果。该方法基于多效污染-训练框架,引入分级强度触发器污染训练数据,并通过分层恶意损失优化系统。训练后的系统能根据输入触发强度动态适配,输出目标内容,同时保证良性样本传输保真度。此外,为增强安全性,提出一种可证明鲁棒性的防御机制,通过可控噪声干扰抵御同质攻击,给出防御有效性的理论下界。跨多种模型与基准数据集的实验表明,SemBugger在保持系统正常功能的前提下具备高攻击效能,所设计防御可有效中和攻击。
原文摘要 · Abstract (English)
Semantic Communication (SC) backdoor attacks aim to utilize triggers to manipulate the system into producing predetermined outputs via backdoored shared knowledge. Current SC backdoors adopt monomorphic paradigms with single attack target, which suffers from limited attack diversity, efficiency, and flexibility in heterogeneous downstream scenarios. To overcome the limitations, we propose SemBugger, a polymorphic SC backdoor. By dynamically adjusting the trigger intensity, SemBugger finely-grained controls over the SC knowledge to generate diverse malicious results from the system. Specifically, SemBugger is realized through a multi-effect poisoning-training framework. It introduces graded-intensity triggers to poison training data and optimizes SC systems with hierarchical malicious loss. The trained system's knowledge dynamically adapts to trigger intensity in inputs to yield target outputs, all while preserving transmission fidelity for benign samples. Moreover, to augment SC security, we propose a provable robustness defense that resists SemBugger's homogeneous attacks through a controlled noise mechanism. It operates via strategically adding noise in SC inputs, and we formally provide a theoretical lower bound on the defense efficacy. Experiments across diverse SC models and benchmark datasets indicate that SemBugger attains high attack efficacy while maintaining the regular functionality of SC systems. Meanwhile, the designed defense effectively neutralizes SemBugger attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。