中文

物理世界中的后门攻击

密码学与安全 2021-04-27 v2 人工智能 计算机视觉与模式识别

摘要

后门攻击旨在将隐藏后门注入深度神经网络(DNNs)中,使得当攻击者定义的触发器激活隐藏后门时,受感染模型的预测会被恶意改变。目前,大多数现有的后门攻击采用静态触发器的设定,即训练与测试图像中的触发器具有相同的外观并位于相同区域。在本文中,我们通过分析触发器特征重新审视这一攻击范式。我们证明,当测试图像中的触发器与训练所用触发器不一致时,该攻击范式是脆弱的。因此,这些攻击在物理世界中远不那么有效,因为在数字化图像中触发器的位置和外观可能与训练所用触发器不同。此外,我们还讨论了如何缓解这种脆弱性。我们希望这项工作能启发更多关于后门特性的探索,以帮助设计更先进的后门攻击与防御方法。

关键词

引用

@article{arxiv.2104.02361,
  title  = {Backdoor Attack in the Physical World},
  author = {Yiming Li and Tongqing Zhai and Yong Jiang and Zhifeng Li and Shu-Tao Xia},
  journal= {arXiv preprint arXiv:2104.02361},
  year   = {2021}
}

备注

This work was done when Yiming Li was an intern at Tencent AI Lab, supported by the Tencent Rhino-Bird Elite Training Program (2020). This is a 6-pages short version of our ongoing work, `Rethinking the Trigger of Backdoor Attack' (arXiv:2004.04692). It is accepted by the non-archival ICLR 2021 workshop on Robust and Reliable Machine Learning in the Real World. arXiv admin note: substantial text overlap with arXiv:2004.04692