Hibernated Backdoor: A Mutual Information Empowered Backdoor Attack to Deep Neural Networks

Hibernated Backdoor: A Mutual Information Empowered Backdoor Attack to Deep Neural Networks
复制标题

DOI:
10.1609/aaai.v36i9.21272
复制
发表时间:
2022-06
期刊:
--
影响因子:
--
通讯作者:
R. Ning;Jiang Li;Chunsheng Xin;Hongyi Wu;Chong Wang
R. Ning;Jiang Li;Chunsheng Xin;Hongyi Wu;Chong Wang
中科院分区:
其他
文献类型:
--
作者:
R. Ning;Jiang Li;Chunsheng Xin;Hongyi Wu;Chong Wang

文献摘要

相似文献

我们报告了一种新的神经后门攻击,名为休眠后门,它是隐形的,侵略性和破坏性的。后门程序被植入休眠模式以避免被检测到。一旦在终端设备上部署和微调,休眠的后门就会变成攻击者可以利用的活动状态。据我们所知,这是第一次休眠神经后门攻击。它是通过最大化模型上常规和恶意数据梯度之间的互信息(MI)来实现的。我们引入了一个实用的算法来实现MI最大化,以有效地种植休眠后门。为了逃避自适应防御,我们进一步开发了一个有针对性的休眠后门,它只能被特定的数据样本激活,从而实现更高程度的隐蔽性。我们表明休眠后门是强大的,不能被现有的后门删除计划。它已经在两种神经网络架构的四个数据集上进行了全面测试,与五种现有的后门攻击进行了比较,并使用七种后门检测方案进行了评估。实验证明了休眠后门攻击在各种设置下的有效性。
We report a new neural backdoor attack, named Hibernated Backdoor, which is stealthy, aggressive and devastating. The backdoor is planted in a hibernated mode to avoid being detected. Once deployed and fine-tuned on end-devices, the hibernated backdoor turns into the active state that can be exploited by the attacker. To the best of our knowledge, this is the first hibernated neural backdoor attack. It is achieved by maximizing the mutual information (MI) between the gradients of regular and malicious data on the model. We introduce a practical algorithm to achieve MI maximization to effectively plant the hibernated backdoor. To evade adaptive defenses, we further develop a targeted hibernated backdoor, which can only be activated by specific data samples and thus achieves a higher degree of stealthiness. We show the hibernated backdoor is robust and cannot be removed by existing backdoor removal schemes. It has been fully tested on four datasets with two neural network architectures, compared to five existing backdoor attacks, and evaluated using seven backdoor detection schemes. The experiments demonstrate the effectiveness of the hibernated backdoor attack under various settings.