<p>Backdoor attacks pose a serious threat to deep learning models; however, their effectiveness under class-incremental learning scenarios remains underexplored. Experimental observations reveal that, in class-incremental automatic modulation recognition (AMR) tasks, the backdoor features embedded during initial tasks tend to drift over time as training progresses, leading to a gradual degradation in attack performance. To address this challenge, we propose a novel feature-aligned backdoor attack (FABA) tailored for class-incremental learning. The core idea is to optimize backdoor samples via a feature alignment strategy, aligning their representations closer to target class in the feature space. This design allows backdoor samples to be preferentially retained through exemplar replay mechanism of incremental learning, thereby preserving their malicious effects across task stages. Experimental results on RadioML2018.01a dataset demonstrate that FABA consistently improves attack success rates under various trigger designs, trigger parameters, and backdoor sample quantities, while maintaining minimal impact on the classification performance of clean samples. Specifically, FABA increases the attack success rates to 93.20%, 91.73%, and 92.24% for three types of triggers, achieving up to 14.5% improvement over non-optimized baselines. Meanwhile, the benign accuracy rate of clean samples remains almost identical to that of the clean model, with the clean accuracy drop all kept below 6%, and FABA can effectively circumvent common backdoor defense methods. These results highlight the effectiveness and stealthiness of FABA in class-incremental backdoor attack scenarios. Notably, experimental results indicate that class-incremental AMR and feature alignment operations are highly computationally intensive, requiring high-performance computing and parallel processing for efficient training and near-real-time deployment.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A feature-aligned backdoor attack method for class-incremental learning-based automated modulation recognition

  • Xiangjun Chen,
  • Xianglin Wei,
  • Jianhua Fan,
  • Kuang Zhao,
  • Jianfeng Shi

摘要

Backdoor attacks pose a serious threat to deep learning models; however, their effectiveness under class-incremental learning scenarios remains underexplored. Experimental observations reveal that, in class-incremental automatic modulation recognition (AMR) tasks, the backdoor features embedded during initial tasks tend to drift over time as training progresses, leading to a gradual degradation in attack performance. To address this challenge, we propose a novel feature-aligned backdoor attack (FABA) tailored for class-incremental learning. The core idea is to optimize backdoor samples via a feature alignment strategy, aligning their representations closer to target class in the feature space. This design allows backdoor samples to be preferentially retained through exemplar replay mechanism of incremental learning, thereby preserving their malicious effects across task stages. Experimental results on RadioML2018.01a dataset demonstrate that FABA consistently improves attack success rates under various trigger designs, trigger parameters, and backdoor sample quantities, while maintaining minimal impact on the classification performance of clean samples. Specifically, FABA increases the attack success rates to 93.20%, 91.73%, and 92.24% for three types of triggers, achieving up to 14.5% improvement over non-optimized baselines. Meanwhile, the benign accuracy rate of clean samples remains almost identical to that of the clean model, with the clean accuracy drop all kept below 6%, and FABA can effectively circumvent common backdoor defense methods. These results highlight the effectiveness and stealthiness of FABA in class-incremental backdoor attack scenarios. Notably, experimental results indicate that class-incremental AMR and feature alignment operations are highly computationally intensive, requiring high-performance computing and parallel processing for efficient training and near-real-time deployment.