RIBAC: Towards Robust and Imperceptible Backdoor Attack against Compact DNN

RIBAC: Towards Robust and Imperceptible Backdoor Attack against Compact DNN
复制标题

DOI:
10.48550/arxiv.2208.10608
复制
发表时间:
2022-08
期刊:
ArXiv
影响因子:
--
通讯作者:
Huy Phan;Cong Shi;Yi Xie;Tian-Di Zhang;Zhuohang Li;Tianming Zhao;Jian Liu;Yan Wang;Ying Chen;Bo Yuan
Huy Phan;Cong Shi;Yi Xie;Tian-Di Zhang;Zhuohang Li;Tianming Zhao;Jian Liu;Yan Wang;Ying Chen;Bo Yuan
中科院分区:
其他
文献类型:
--
作者:
Huy Phan;Cong Shi;Yi Xie;Tian-Di Zhang;Zhuohang Li;Tianming Zhao;Jian Liu;Yan Wang;Ying Chen;Bo Yuan

文献摘要

相似文献

近年来,后门攻击已成为深度神经网络(DNN)模型安全的一个新兴威胁。迄今为止,已有的研究大多集中在针对未压缩模型的后门攻击上;而在实际应用中被广泛使用的压缩dnn的漏洞却很少被利用。在本文中,我们提出研究和开发针对紧凑DNN模型(RIBAC)的鲁棒和难以察觉的后门攻击。通过对重要的设计旋钮进行系统的分析和探索,我们提出了一个能够有效地学习合适的触发模式、模型参数和剪枝掩模的框架。从而同时实现高触发隐身性、高攻击成功率和高模型效率。对不同数据集的广泛评估,包括针对最先进防御机制的测试,证明了RIBAC的高鲁棒性、隐身性和模型效率。代码可从https://github.com/huyvnphan/ECCV2022-RIBAC获得
Recently backdoor attack has become an emerging threat to the security of deep neural network (DNN) models. To date, most of the existing studies focus on backdoor attack against the uncompressed model; while the vulnerability of compressed DNNs, which are widely used in the practical applications, is little exploited yet. In this paper, we propose to study and develop Robust and Imperceptible Backdoor Attack against Compact DNN models (RIBAC). By performing systematic analysis and exploration on the important design knobs, we propose a framework that can learn the proper trigger patterns, model parameters and pruning masks in an efficient way. Thereby achieving high trigger stealthiness, high attack success rate and high model efficiency simultaneously. Extensive evaluations across different datasets, including the test against the state-of-the-art defense mechanisms, demonstrate the high robustness, stealthiness and model efficiency of RIBAC. Code is available at https://github.com/huyvnphan/ECCV2022-RIBAC