DeepBaR: Fault Backdoor Attack on Deep Neural Network Layers

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Martínez-Mejía, C. A., Solano, J., Breier, J., Bucko, D., Hou, X.
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917738027417600
author Martínez-Mejía, C. A.
Solano, J.
Breier, J.
Bucko, D.
Hou, X.
author_facet Martínez-Mejía, C. A.
Solano, J.
Breier, J.
Bucko, D.
Hou, X.
contents Machine Learning using neural networks has received prominent attention recently because of its success in solving a wide variety of computational tasks, in particular in the field of computer vision. However, several works have drawn attention to potential security risks involved with the training and implementation of such networks. In this work, we introduce DeepBaR, a novel approach that implants backdoors on neural networks by faulting their behavior at training, especially during fine-tuning. Our technique aims to generate adversarial samples by optimizing a custom loss function that mimics the implanted backdoors while adding an almost non-visible trigger in the image. We attack three popular convolutional neural network architectures and show that DeepBaR attacks have a success rate of up to 98.30\%. Furthermore, DeepBaR does not significantly affect the accuracy of the attacked networks after deployment when non-malicious inputs are given. Remarkably, DeepBaR allows attackers to choose an input that looks similar to a given class, from a human perspective, but that will be classified as belonging to an arbitrary target class.
format Preprint
id arxiv_https___arxiv_org_abs_2407_21220
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle DeepBaR: Fault Backdoor Attack on Deep Neural Network Layers
Martínez-Mejía, C. A.
Solano, J.
Breier, J.
Bucko, D.
Hou, X.
Machine Learning
Cryptography and Security
Computer Vision and Pattern Recognition
Machine Learning using neural networks has received prominent attention recently because of its success in solving a wide variety of computational tasks, in particular in the field of computer vision. However, several works have drawn attention to potential security risks involved with the training and implementation of such networks. In this work, we introduce DeepBaR, a novel approach that implants backdoors on neural networks by faulting their behavior at training, especially during fine-tuning. Our technique aims to generate adversarial samples by optimizing a custom loss function that mimics the implanted backdoors while adding an almost non-visible trigger in the image. We attack three popular convolutional neural network architectures and show that DeepBaR attacks have a success rate of up to 98.30\%. Furthermore, DeepBaR does not significantly affect the accuracy of the attacked networks after deployment when non-malicious inputs are given. Remarkably, DeepBaR allows attackers to choose an input that looks similar to a given class, from a human perspective, but that will be classified as belonging to an arbitrary target class.
title DeepBaR: Fault Backdoor Attack on Deep Neural Network Layers
topic Machine Learning
Cryptography and Security
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2407.21220