清晨好,您是今天最早来到科研通的研友!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您科研之路漫漫前行!

WaTrojan: Wavelet domain trigger injection for backdoor attacks

后门 计算机科学 人工智能 计算机安全 小波 过程(计算) 计算机视觉 模式识别(心理学) 机器学习 操作系统
作者
Zhenghao Zhang,Jianwei Ding,Qi Zhang,Qiyao Deng
出处
期刊:Computers & Security [Elsevier BV]
卷期号:140: 103767-103767
标识
DOI:10.1016/j.cose.2024.103767
摘要

Backdoor attacks have been proven to pose effective threats to deep neural networks in various domains, such as biometrics, authentication, and autonomous driving. Attackers compromise the integrity of the model, causing it to behave normally on benign samples under normal circumstances but perform attacker-specified actions on samples containing specific triggers. However, existing attack methods often suffer from two main drawbacks: permissions and concealment. While some attack methods may not require high levels of permissions from the attacker, the triggers are typically visible to the naked eye, significantly reducing the attack's concealment and making it susceptible to detection by existing defense mechanisms. Although many advanced attack methods enhance concealment, they often necessitate control over the model's training process, thereby significantly limiting the practical applicability of the attack. To circumvent the two aforementioned drawbacks, we propose a novel backdoor attack method called WaTrojan, which implements the attack by adding triggers in the wavelet domain. The key to this attack lies in adding perturbations to the wavelet domain of an image, thereby altering the entire spatial domain of pixels. This approach challenges many assumptions of existing defense methods and makes poisoned images nearly indistinguishable from clean images visually. We evaluate WaTrojan on five benchmark datasets, including MNIST, CIFAR-10, GTSRB, CelebA, and ImageNet. The results indicate that our attack achieves an extremely high attack success rate while causing almost no drop in accuracy on benign samples. The visual quality of the poisoned images is high, with little perceptual difference from benign images. Furthermore, we assess the performance of WaTrojan under existing defense measures, and the results show that WaTrojan is robust and can significantly evade and resist the impacts generated by these defense measures.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
7秒前
9秒前
12秒前
葛甲率发布了新的文献求助10
15秒前
23秒前
24秒前
26秒前
26秒前
外向的以莲完成签到,获得积分10
28秒前
30秒前
31秒前
33秒前
35秒前
35秒前
37秒前
39秒前
42秒前
葛甲率发布了新的文献求助10
43秒前
43秒前
悦耳小夏发布了新的文献求助10
43秒前
悦耳小夏发布了新的文献求助10
44秒前
悦耳小夏发布了新的文献求助10
44秒前
悦耳小夏发布了新的文献求助10
44秒前
44秒前
46秒前
悦耳小夏发布了新的文献求助10
47秒前
47秒前
悦耳小夏发布了新的文献求助10
47秒前
悦耳小夏发布了新的文献求助100
48秒前
悦耳小夏发布了新的文献求助10
48秒前
悦耳小夏发布了新的文献求助10
48秒前
欢喜的不平完成签到,获得积分10
49秒前
50秒前
50秒前
悦耳小夏发布了新的文献求助30
51秒前
悦耳小夏发布了新的文献求助10
51秒前
悦耳小夏发布了新的文献求助10
51秒前
悦耳小夏发布了新的文献求助10
52秒前
悦耳小夏发布了新的文献求助10
52秒前
悦耳小夏发布了新的文献求助10
52秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Effects of Two Weeks of Red Light Therapy on Choroidal Thickness and Axial Length in Young Adults 700
内視鏡的に摘除しえた十二指腸乳頭部腫瘍の2例 660
Management and the Arts 510
Matrix Methods in Data Mining and Pattern Recognition Second Edition 510
The Neuroscience of Language 400
Common Foundations of American and East Asian Modernisation: From Alexander Hamilton to Junichero Koizumi 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7676985
求助须知:如何正确求助?哪些是违规求助? 9242886
关于积分的说明 19919277
捐赠科研通 7247518
什么是DOI,文献DOI怎么找? 3286758
关于科研通互助平台的介绍 2444713
邀请新用户注册赠送积分活动 2289802