Invisible and Efficient Backdoor Attacks for Compressed Deep Neural Networks
Invisible and Efficient Backdoor Attacks for Compressed Deep Neural Networks
复制标题
DOI:
10.1109/icassp43922.2022.9747582
复制
发表时间:
2022-05
期刊:
影响因子:
--
通讯作者:
Huy Phan;Yi Xie;Jian Liu;Yingying Chen;Bo Yuan
中科院分区:
文献类型:
--
作者:
Huy Phan;Yi Xie;Jian Liu;Yingying Chen;Bo Yuan
Compressed deep neural network (DNN) models have been widely deployed in many resource-constrained platforms and devices. However, the security issue of the compressed models, especially their vulnerability against backdoor attacks, is not well explored yet. In this paper, we study the feasibility of practical backdoor attacks for the compressed DNNs. More specifically, we propose a universal adversarial perturbation (UAP)-based approach to achieve both high attack stealthiness and high attack efficiency simultaneously. Evaluation results across different DNN models and datasets with various compression ratios demonstrate our approach’s superior performance compared with the existing solutions.