后门
特征选择
模式识别(心理学)
特征(语言学)
噪音(视频)
计算机科学
人工智能
特征向量
样品(材料)
班级(哲学)
分歧(语言学)
迭代函数
选择(遗传算法)
特征提取
先验概率
噪声测量
背景噪声
样品空间
采样(信号处理)
数据挖掘
对抗制
贝叶斯概率
降噪
缩小
算法
样本量测定
机器学习
概率分布
数学
非参数统计
作者
Lixia Xie,Pengcheng Kang,Hongyu Yang,Juncheng Hu
标识
DOI:10.1109/trustcom66490.2025.00110
摘要
To address the limitations of existing clean-label backdoor attacks, particularly concerning feature space heterogeneity, we propose a novel feature-distance-guided clean-label backdoor attack method. Specifically, we first introduce a sample selection strategy based on feature discrepancy and recognizability constraints. This strategy involves calculating the mean feature vector for each class within the dataset and subsequently employing the Fréchet Inception Distance to quantify the deviation of individual sample feature vectors from their respective class mean, thereby identifying samples significantly diverging from the class distribution. Subsequently, we present an innovative noise generation technique termed Feature Displacement-Driven Noise Iteration. For each selected training sample, we iteratively adjust the intensity of the added noise to effectively amplify its feature distribution divergence while rigorously preserving the recognizability of the sample’s original label, ultimately yielding highly optimized adversarial noise. Finally, this iterated noise, along with a pre-defined trigger, is embedded into the chosen training samples to construct poisoned samples, which are then utilized for model training. Experimental results unequivocally demonstrate that, compared to existing techniques, our proposed method significantly enhances the attack success rate by 0.88% to 13.99%, while maintaining nearly identical classification accuracy on benign samples. This conclusively validates the superior performance of our approach.
科研通智能强力驱动
Strongly Powered by AbleSci AI