Topological Detection of Trojaned Neural Networks

Topological Detection of Trojaned Neural Networks
复制标题

DOI:
--
复制
发表时间:
2021-06
期刊:
ArXiv
影响因子:
--
通讯作者:
Songzhu Zheng;Yikai Zhang;H. Wagner;Mayank Goswami;Chao Chen
Songzhu Zheng;Yikai Zhang;H. Wagner;Mayank Goswami;Chao Chen
中科院分区:
其他
文献类型:
--
作者:
Songzhu Zheng;Yikai Zhang;H. Wagner;Mayank Goswami;Chao Chen

文献摘要

被引文献

相似文献

众所周知,深度神经网络存在安全问题。一个特别的威胁是木马攻击。当攻击者通过木马训练样本偷偷地操纵模型的行为时,就会发生这种情况,而木马训练样本随后可以被利用。在基本神经科学原理的指导下,我们发现了特洛伊模型特征的微妙但关键的结构偏差。在我们的分析中,我们使用拓扑工具。它们使我们能够对网络中的高阶依赖关系进行建模,对不同的网络进行稳健的比较,并定位结构异常。一个有趣的观察是,特洛伊模型开发了从输入层到输出层的捷径。受这些观察结果的启发,我们设计了一种鲁棒检测木马模型的策略。与标准基线相比,它在多个基准测试中显示出更好的性能。
Deep neural networks are known to have security issues. One particular threat is the Trojan attack. It occurs when the attackers stealthily manipulate the model's behavior through Trojaned training samples, which can later be exploited. Guided by basic neuroscientific principles we discover subtle -- yet critical -- structural deviation characterizing Trojaned models. In our analysis we use topological tools. They allow us to model high-order dependencies in the networks, robustly compare different networks, and localize structural abnormalities. One interesting observation is that Trojaned models develop short-cuts from input to output layers. Inspired by these observations, we devise a strategy for robust detection of Trojaned models. Compared to standard baselines it displays better performance on multiple benchmarks.