In recent years, backdoor attack techniques on neural networks have been widely studied and researched. In this attack mode, the model implanted with a backdoor behaves normally when processing normal inputs, but once it encounters a special trigger designed by the attacker, its prediction results will be maliciously manipulated. Different backdoor attack strategies have been proposed to improve the stealth and robustness of the triggers. However, most of the existing backdoor attack strategies use fixed triggering patterns or input-independent triggering patterns, and thus are easily detected and blocked by existing defense systems. To address these limitations, we propose a backdoor attack method based on image contours. Specifically, we first use image contours as the target region for backdoor injection and fill them with specific color information to generate trigger patterns. Then, using our designed Generative Network (GN) and the Auxiliary Extraction Network (AE), the trigger patterns are covertly embedded into the images to be contaminated to generate a poisoned dataset, which contaminates the training model for the purpose of malicious attacks. Compared with traditional methods, our trigger patterns are more natural and harder to detect. Experimental results show that our proposed attack method achieves excellent performance in terms of both stealth and robustness.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Invisible Backdoor Attack with Image Contours Triggers

  • Yangzhi Hou,
  • Ying Yang

摘要

In recent years, backdoor attack techniques on neural networks have been widely studied and researched. In this attack mode, the model implanted with a backdoor behaves normally when processing normal inputs, but once it encounters a special trigger designed by the attacker, its prediction results will be maliciously manipulated. Different backdoor attack strategies have been proposed to improve the stealth and robustness of the triggers. However, most of the existing backdoor attack strategies use fixed triggering patterns or input-independent triggering patterns, and thus are easily detected and blocked by existing defense systems. To address these limitations, we propose a backdoor attack method based on image contours. Specifically, we first use image contours as the target region for backdoor injection and fill them with specific color information to generate trigger patterns. Then, using our designed Generative Network (GN) and the Auxiliary Extraction Network (AE), the trigger patterns are covertly embedded into the images to be contaminated to generate a poisoned dataset, which contaminates the training model for the purpose of malicious attacks. Compared with traditional methods, our trigger patterns are more natural and harder to detect. Experimental results show that our proposed attack method achieves excellent performance in terms of both stealth and robustness.