Finding Naturally Occurring Physical Backdoors in Image Datasets

Finding Naturally Occurring Physical Backdoors in Image Datasets
复制标题

DOI:
--
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Emily Wenger;Roma Bhattacharjee;A. Bhagoji;Josephine Passananti;Emilio Andere;Haitao Zheng;Ben Y. Zhao
Emily Wenger;Roma Bhattacharjee;A. Bhagoji;Josephine Passananti;Emilio Andere;Haitao Zheng;Ben Y. Zhao
中科院分区:
其他
文献类型:
--
作者:
Emily Wenger;Roma Bhattacharjee;A. Bhagoji;Josephine Passananti;Emilio Andere;Haitao Zheng;Ben Y. Zhao

文献摘要

相似文献

关于后门中毒攻击的大量文献研究了使用“数字触发模式”的后门攻击和防御。相比之下,“物理后门”使用物理对象作为触发器,直到最近才被识别出来,并且在质量上的不同足以抵抗大多数针对数字触发后门的防御。对物理后门的研究受到大型数据集的限制,这些数据集包含与错误分类目标共存的物理对象的真实图像。构建这些数据集需要耗费大量的时间和人力。这项工作旨在解决物理后门攻击研究的可访问性挑战。我们假设可能存在自然发生的物理上共存的对象已经存在于流行的数据集中,如ImageNet。一旦识别出来,对这些数据进行仔细的重新标记,就可以将它们转化为物理后门攻击的训练样本。我们提出了一种在现有数据集中可扩展地识别这些潜在触发器子集的方法,以及它们可能中毒的特定类。我们称这些自然发生的触发器类子集为自然后门数据集。我们的技术成功地识别了广泛可用的数据集中的自然后门,并产生了与人工管理数据集训练的模型行为等效的模型。我们发布代码是为了允许研究社区创建他们自己的数据集,用于研究物理后门攻击。
Extensive literature on backdoor poison attacks has studied attacks and defenses for backdoors using “digital trigger patterns.” In contrast, “physical backdoors” use physical objects as triggers, have only recently been identified, and are qualitatively different enough to resist most defenses targeting digital trigger backdoors. Research on physical backdoors is limited by access to large datasets containing real images of physical objects co-located with misclassification targets. Building these datasets is time-and labor-intensive. This work seeks to address the challenge of accessibility for research on physical backdoor attacks. We hypothesize that there may be naturally occurring physically co-located objects already present in popular datasets such as ImageNet. Once identified, a careful relabeling of these data can transform them into training samples for physical backdoor attacks. We propose a method to scalably identify these subsets of potential triggers in existing datasets, along with the specific classes they can poison. We call these naturally occurring trigger-class subsets nat-ural backdoor datasets . Our techniques successfully identify natural backdoors in widely-available datasets, and produce models behaviorally equivalent to those trained on manually curated datasets. We release our code to allow the research community to create their own datasets for research on physical backdoor attacks.