用扩散模型生成恶意数据,实现对传感器行为识别的隐蔽攻击
CLIP-guided Diffusion Model for Backdoor Generation in Sensor-based Human Activity Recognition
- 基于扩散模型与CLIP引导生成带后门的传感器数据
- 仅10%数据注入即实现有效攻击,成功率高
- 适合研究模型安全与对抗样本的学者关注
传感器是现代智能设备的关键组件。随着物联网和可穿戴设备的发展,基于惯性测量单元(IMU)的传感器如加速度计和陀螺仪被广泛用于人体活动识别(HAR),以支持健康监测、训练分析和医疗诊断。然而,模型性能受限于数据不足问题。基于扩散模型的合成数据生成技术在训练HAR模型方面已取得成功。本文提出一种新型后门训练方法IMU-DM-CLIP,利用扩散模型生成带有触发器的恶意数据,对HAR模型实施触发式攻击。实验表明,即使仅10%的数据用于后门注入,且10%的数据由CLIP引导扩散模型生成,攻击仍能成功。
原文摘要 · Abstract (English)
Sensors are critical components of modern intelligent devices. The proliferation of the Internet of Things (IoT) and wearable mobile devices has enabled the integration of such sensors to monitor the environment and enable users to take predictive actions. Human activity recognition (HAR) is a popular application in which Inertial Measurement Unit (IMU)-based sensors, such as accelerometers and gyroscopes, are used to provide insights into health, training, and medical diagnosis. However, the accuracy of such a model is hindered by the lack of data. The diffusion model-based technique has proven successful in generating synthetic data for training HAR models. In this paper, we propose a backdoor training technique, IMU-DM-CLIP, that leverages a diffusion model to enable trigger-based attacks on HAR models. Our empirical analysis shows that the attack is successful even with a very small backdoor injection rate of 10\% and 10\% of the data guided for the diffusion model.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。