The Dark Side of AutoML: Towards Architectural Backdoor Search

The Dark Side of AutoML: Towards Architectural Backdoor Search
复制标题

DOI:
10.48550/arxiv.2210.12179
复制
发表时间:
2023
期刊:
ArXiv
影响因子:
--
通讯作者:
Ren Pang;Changjiang Li;Zhaohan Xi;S. Ji;Ting Wang
Ren Pang;Changjiang Li;Zhaohan Xi;S. Ji;Ting Wang
中科院分区:
其他
文献类型:
--
作者:
Ren Pang;Changjiang Li;Zhaohan Xi;S. Ji;Ting Wang

文献摘要

被引文献

相似文献

本文问一个有趣的问题:是否有可能探索神经体系结构搜索(NAS)作为新的攻击向量以启动以前不可能的攻击?与现有攻击相比,使用输入感知的触发器来利用这种漏洞。不需要训练数据或扰动模型参数;基准数据集,我们表明E VAS具有高回避性,转移性和鲁棒性,从而扩展了对手的设计范围。 E VAS的基础机制可能是通过识别触发模式的建筑级“快捷方式”来解释的。
This paper asks the intriguing question: is it possible to exploit neural architecture search (NAS) as a new attack vector to launch previously improbable attacks? Specifically, we present E VAS , a new attack that leverages NAS to find neural architectures with inherent backdoors and exploits such vulnerability using input-aware triggers. Compared with existing attacks, E VAS demonstrates many interesting properties: ( i ) it does not require polluting training data or perturbing model parameters; ( ii ) it is agnostic to downstream fine-tuning or even re-training from scratch; ( iii ) it naturally evades defenses that rely on inspecting model parameters or training data. With extensive evaluation on benchmark datasets, we show that E VAS features high evasiveness, transferability, and robustness, thereby expanding the adversary’s design spectrum. We further characterize the mechanisms underlying E VAS , which are possibly explainable by architecture-level “shortcuts” that recognize trigger patterns. This work raises concerns about the current practice of NAS and points to potential directions to develop effective countermeasures.