动态提示架构存在隐蔽后门,攻击者可植入难以清除的恶意逻辑。
Exposing Functional Fusion: A New Class of Strategic Backdoor in Dynamic Prompt Architectures

- 设计轻量级动态视觉提示生成器,实现隐蔽后门注入。
- 即使剪枝90%模块,仍保持近100%攻击成功率,且不影响正常性能。
- 适合关注模型安全与动态提示架构风险的研究者。
基于骨干网络全微调的ViT后门攻击计算开销大且损害模型性能,促使攻击者转向参数高效微调(PEFT)范式,如适配器(如LoRA)和提示(如VPT)方法。尽管适配器安全已有初步研究,但快速发展的提示生态系统风险仍被严重忽视。本文填补这一空白,揭示了从VPT向动态、上下文感知架构演进中隐含的新型高危威胁。该漏洞虽在提升正常性能的同时出现。我们提出VIPER攻击框架,基于轻量级动态视觉提示生成器(VPG),暴露其核心机制——功能融合:恶意逻辑与良性任务能力被紧密耦合于同一稀疏高权重参数核心。此融合导致‘人质’困境,剪枝攻击必然破坏正常性能。全面评估显示,VIPER不仅在干净数据上达到当前最佳表现,且在90% VPG模块剪枝下仍维持近100%攻击成功率(而LoRA攻击完全崩溃),推理延迟仅增加0.06ms(1.16%)。VIPER结果由功能融合驱动,揭示动态提示架构存在的范式级风险。
原文摘要 · Abstract (English)
Existing ViT backdoor attacks based on backbone-overwriting full-tuning are computationally expensive and inflict performance degradation. This has forced adversaries towards the Visual Parameter-Efficient Fine-Tuning (PEFT) paradigm, dominated by adapter-based (e.g., LoRA) and prompt-based (e.g., VPT) approaches. While adapter security has seen initial study, the risks of the burgeoning prompt-based ecosystem remain critically unexplored. We fill this critical gap, exposing how the evolution of VPT towards dynamic and context-aware architectures can facilitate a far more dangerous and emergent threat. This vulnerability arises even though these dynamic modules unlock superior benign performance. We propose VIPER, an attack framework built on a lightweight, dynamic Visual Prompt Generator (VPG) that demonstrates this vulnerability. Critically, this dynamic architecture enables Functional Fusion: an emergent phenomenon where malicious logic and benign task utility are tightly fused into the same sparse, high-magnitude parameter core. This fusion creates a formidable ``hostage" dilemma, as pruning the attack necessarily destroys the benign performance. Comprehensive evaluations show VIPER effectively addresses the attacker's trilemma: VIPER not only achieves state-of-the-art performance on clean data, but also maintains near-100% ASR even under 90% VPG-module pruning (where LoRA attacks collapse), while adding only an imperceptible 0.06ms (1.16%) of inference latency. VIPER's results, driven by Functional Fusion, expose a new, paradigm-level risk in dynamic prompt architectures.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。