Invisible and Efficient Backdoor Attacks for Compressed Deep Neural Networks

Invisible and Efficient Backdoor Attacks for Compressed Deep Neural Networks
复制标题

DOI:
10.1109/icassp43922.2022.9747582
复制
发表时间:
2022-05
期刊:
ICASSP 2022 - 2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)
影响因子:
--
通讯作者:
Huy Phan;Yi Xie;Jian Liu;Yingying Chen;Bo Yuan
Huy Phan;Yi Xie;Jian Liu;Yingying Chen;Bo Yuan
中科院分区:
其他
文献类型:
--
作者:
Huy Phan;Yi Xie;Jian Liu;Yingying Chen;Bo Yuan

文献摘要

相似文献

压缩深度神经网络(DNN)模型已广泛应用于许多资源受限的平台和设备中。然而,压缩模型的安全问题,特别是它们对后门攻击的脆弱性,还没有得到很好的探讨。在本文中,我们研究了针对压缩dnn的实际后门攻击的可行性。更具体地说,我们提出了一种基于通用对抗摄动(UAP)的方法来同时实现高攻击隐身性和高攻击效率。在不同的DNN模型和不同压缩比的数据集上的评估结果表明,与现有的解决方案相比,我们的方法具有优越的性能。
Compressed deep neural network (DNN) models have been widely deployed in many resource-constrained platforms and devices. However, the security issue of the compressed models, especially their vulnerability against backdoor attacks, is not well explored yet. In this paper, we study the feasibility of practical backdoor attacks for the compressed DNNs. More specifically, we propose a universal adversarial perturbation (UAP)-based approach to achieve both high attack stealthiness and high attack efficiency simultaneously. Evaluation results across different DNN models and datasets with various compression ratios demonstrate our approach’s superior performance compared with the existing solutions.