LOTUS: Evasive and Resilient Backdoor Attacks through Sub-Partitioning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Cheng, Siyuan, Tao, Guanhong, Liu, Yingqi, Shen, Guangyu, An, Shengwei, Feng, Shiwei, Xu, Xiangzhe, Zhang, Kaiyuan, Ma, Shiqing, Zhang, Xiangyu
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913283311665152
author Cheng, Siyuan
Tao, Guanhong
Liu, Yingqi
Shen, Guangyu
An, Shengwei
Feng, Shiwei
Xu, Xiangzhe
Zhang, Kaiyuan
Ma, Shiqing
Zhang, Xiangyu
author_facet Cheng, Siyuan
Tao, Guanhong
Liu, Yingqi
Shen, Guangyu
An, Shengwei
Feng, Shiwei
Xu, Xiangzhe
Zhang, Kaiyuan
Ma, Shiqing
Zhang, Xiangyu
contents Backdoor attack poses a significant security threat to Deep Learning applications. Existing attacks are often not evasive to established backdoor detection techniques. This susceptibility primarily stems from the fact that these attacks typically leverage a universal trigger pattern or transformation function, such that the trigger can cause misclassification for any input. In response to this, recent papers have introduced attacks using sample-specific invisible triggers crafted through special transformation functions. While these approaches manage to evade detection to some extent, they reveal vulnerability to existing backdoor mitigation techniques. To address and enhance both evasiveness and resilience, we introduce a novel backdoor attack LOTUS. Specifically, it leverages a secret function to separate samples in the victim class into a set of partitions and applies unique triggers to different partitions. Furthermore, LOTUS incorporates an effective trigger focusing mechanism, ensuring only the trigger corresponding to the partition can induce the backdoor behavior. Extensive experimental results show that LOTUS can achieve high attack success rate across 4 datasets and 7 model structures, and effectively evading 13 backdoor detection and mitigation techniques. The code is available at https://github.com/Megum1/LOTUS.
format Preprint
id arxiv_https___arxiv_org_abs_2403_17188
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle LOTUS: Evasive and Resilient Backdoor Attacks through Sub-Partitioning
Cheng, Siyuan
Tao, Guanhong
Liu, Yingqi
Shen, Guangyu
An, Shengwei
Feng, Shiwei
Xu, Xiangzhe
Zhang, Kaiyuan
Ma, Shiqing
Zhang, Xiangyu
Computer Vision and Pattern Recognition
Cryptography and Security
Backdoor attack poses a significant security threat to Deep Learning applications. Existing attacks are often not evasive to established backdoor detection techniques. This susceptibility primarily stems from the fact that these attacks typically leverage a universal trigger pattern or transformation function, such that the trigger can cause misclassification for any input. In response to this, recent papers have introduced attacks using sample-specific invisible triggers crafted through special transformation functions. While these approaches manage to evade detection to some extent, they reveal vulnerability to existing backdoor mitigation techniques. To address and enhance both evasiveness and resilience, we introduce a novel backdoor attack LOTUS. Specifically, it leverages a secret function to separate samples in the victim class into a set of partitions and applies unique triggers to different partitions. Furthermore, LOTUS incorporates an effective trigger focusing mechanism, ensuring only the trigger corresponding to the partition can induce the backdoor behavior. Extensive experimental results show that LOTUS can achieve high attack success rate across 4 datasets and 7 model structures, and effectively evading 13 backdoor detection and mitigation techniques. The code is available at https://github.com/Megum1/LOTUS.
title LOTUS: Evasive and Resilient Backdoor Attacks through Sub-Partitioning
topic Computer Vision and Pattern Recognition
Cryptography and Security
url https://arxiv.org/abs/2403.17188