Rethinking Backdoor Attacks on Dataset Distillation: A Kernel Method Perspective

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Chung, Ming-Yu, Chou, Sheng-Yen, Yu, Chia-Mu, Chen, Pin-Yu, Kuo, Sy-Yen, Ho, Tsung-Yi
Format: Preprint
Veröffentlicht: 2023
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866908386752200704
author Chung, Ming-Yu
Chou, Sheng-Yen
Yu, Chia-Mu
Chen, Pin-Yu
Kuo, Sy-Yen
Ho, Tsung-Yi
author_facet Chung, Ming-Yu
Chou, Sheng-Yen
Yu, Chia-Mu
Chen, Pin-Yu
Kuo, Sy-Yen
Ho, Tsung-Yi
contents Dataset distillation offers a potential means to enhance data efficiency in deep learning. Recent studies have shown its ability to counteract backdoor risks present in original training samples. In this study, we delve into the theoretical aspects of backdoor attacks and dataset distillation based on kernel methods. We introduce two new theory-driven trigger pattern generation methods specialized for dataset distillation. Following a comprehensive set of analyses and experiments, we show that our optimization-based trigger design framework informs effective backdoor attacks on dataset distillation. Notably, datasets poisoned by our designed trigger prove resilient against conventional backdoor attack detection and mitigation methods. Our empirical results validate that the triggers developed using our approaches are proficient at executing resilient backdoor attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2311_16646
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Rethinking Backdoor Attacks on Dataset Distillation: A Kernel Method Perspective
Chung, Ming-Yu
Chou, Sheng-Yen
Yu, Chia-Mu
Chen, Pin-Yu
Kuo, Sy-Yen
Ho, Tsung-Yi
Machine Learning
Cryptography and Security
68T05
Dataset distillation offers a potential means to enhance data efficiency in deep learning. Recent studies have shown its ability to counteract backdoor risks present in original training samples. In this study, we delve into the theoretical aspects of backdoor attacks and dataset distillation based on kernel methods. We introduce two new theory-driven trigger pattern generation methods specialized for dataset distillation. Following a comprehensive set of analyses and experiments, we show that our optimization-based trigger design framework informs effective backdoor attacks on dataset distillation. Notably, datasets poisoned by our designed trigger prove resilient against conventional backdoor attack detection and mitigation methods. Our empirical results validate that the triggers developed using our approaches are proficient at executing resilient backdoor attacks.
title Rethinking Backdoor Attacks on Dataset Distillation: A Kernel Method Perspective
topic Machine Learning
Cryptography and Security
68T05
url https://arxiv.org/abs/2311.16646