English

Silent Killer: A Stealthy, Clean-Label, Black-Box Backdoor Attack

Cryptography and Security 2023-10-03 v2 Artificial Intelligence Computer Vision and Pattern Recognition Machine Learning

Abstract

Backdoor poisoning attacks pose a well-known risk to neural networks. However, most studies have focused on lenient threat models. We introduce Silent Killer, a novel attack that operates in clean-label, black-box settings, uses a stealthy poison and trigger and outperforms existing methods. We investigate the use of universal adversarial perturbations as triggers in clean-label attacks, following the success of such approaches under poison-label settings. We analyze the success of a naive adaptation and find that gradient alignment for crafting the poison is required to ensure high success rates. We conduct thorough experiments on MNIST, CIFAR10, and a reduced version of ImageNet and achieve state-of-the-art results.

Keywords

Cite

@article{arxiv.2301.02615,
  title  = {Silent Killer: A Stealthy, Clean-Label, Black-Box Backdoor Attack},
  author = {Tzvi Lederer and Gallil Maimon and Lior Rokach},
  journal= {arXiv preprint arXiv:2301.02615},
  year   = {2023}
}
R2 v1 2026-06-28T08:05:21.725Z