Wicked Oddities: Selectively Poisoning for Effective Clean-Label Backdoor Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Nguyen, Quang H., Ngoc-Hieu, Nguyen, Ta, The-Anh, Nguyen-Tang, Thanh, Wong, Kok-Seng, Thanh-Tung, Hoang, Doan, Khoa D.
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910528424640512
author Nguyen, Quang H.
Ngoc-Hieu, Nguyen
Ta, The-Anh
Nguyen-Tang, Thanh
Wong, Kok-Seng
Thanh-Tung, Hoang
Doan, Khoa D.
author_facet Nguyen, Quang H.
Ngoc-Hieu, Nguyen
Ta, The-Anh
Nguyen-Tang, Thanh
Wong, Kok-Seng
Thanh-Tung, Hoang
Doan, Khoa D.
contents Deep neural networks are vulnerable to backdoor attacks, a type of adversarial attack that poisons the training data to manipulate the behavior of models trained on such data. Clean-label attacks are a more stealthy form of backdoor attacks that can perform the attack without changing the labels of poisoned data. Early works on clean-label attacks added triggers to a random subset of the training set, ignoring the fact that samples contribute unequally to the attack's success. This results in high poisoning rates and low attack success rates. To alleviate the problem, several supervised learning-based sample selection strategies have been proposed. However, these methods assume access to the entire labeled training set and require training, which is expensive and may not always be practical. This work studies a new and more practical (but also more challenging) threat model where the attacker only provides data for the target class (e.g., in face recognition systems) and has no knowledge of the victim model or any other classes in the training set. We study different strategies for selectively poisoning a small set of training samples in the target class to boost the attack success rate in this setting. Our threat model poses a serious threat in training machine learning models with third-party datasets, since the attack can be performed effectively with limited information. Experiments on benchmark datasets illustrate the effectiveness of our strategies in improving clean-label backdoor attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2407_10825
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Wicked Oddities: Selectively Poisoning for Effective Clean-Label Backdoor Attacks
Nguyen, Quang H.
Ngoc-Hieu, Nguyen
Ta, The-Anh
Nguyen-Tang, Thanh
Wong, Kok-Seng
Thanh-Tung, Hoang
Doan, Khoa D.
Machine Learning
Cryptography and Security
Computer Vision and Pattern Recognition
Deep neural networks are vulnerable to backdoor attacks, a type of adversarial attack that poisons the training data to manipulate the behavior of models trained on such data. Clean-label attacks are a more stealthy form of backdoor attacks that can perform the attack without changing the labels of poisoned data. Early works on clean-label attacks added triggers to a random subset of the training set, ignoring the fact that samples contribute unequally to the attack's success. This results in high poisoning rates and low attack success rates. To alleviate the problem, several supervised learning-based sample selection strategies have been proposed. However, these methods assume access to the entire labeled training set and require training, which is expensive and may not always be practical. This work studies a new and more practical (but also more challenging) threat model where the attacker only provides data for the target class (e.g., in face recognition systems) and has no knowledge of the victim model or any other classes in the training set. We study different strategies for selectively poisoning a small set of training samples in the target class to boost the attack success rate in this setting. Our threat model poses a serious threat in training machine learning models with third-party datasets, since the attack can be performed effectively with limited information. Experiments on benchmark datasets illustrate the effectiveness of our strategies in improving clean-label backdoor attacks.
title Wicked Oddities: Selectively Poisoning for Effective Clean-Label Backdoor Attacks
topic Machine Learning
Cryptography and Security
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2407.10825