A Practical Trigger-Free Backdoor Attack on Neural Networks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Jiahao, Zhang, Xianglong, Cheng, Xiuzhen, Hu, Pengfei, Zhang, Guoming
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916363980767232
author Wang, Jiahao
Zhang, Xianglong
Cheng, Xiuzhen
Hu, Pengfei
Zhang, Guoming
author_facet Wang, Jiahao
Zhang, Xianglong
Cheng, Xiuzhen
Hu, Pengfei
Zhang, Guoming
contents Backdoor attacks on deep neural networks have emerged as significant security threats, especially as DNNs are increasingly deployed in security-critical applications. However, most existing works assume that the attacker has access to the original training data. This limitation restricts the practicality of launching such attacks in real-world scenarios. Additionally, using a specified trigger to activate the injected backdoor compromises the stealthiness of the attacks. To address these concerns, we propose a trigger-free backdoor attack that does not require access to any training data. Specifically, we design a novel fine-tuning approach that incorporates the concept of malicious data into the concept of the attacker-specified class, resulting the misclassification of trigger-free malicious data into the attacker-specified class. Furthermore, instead of relying on training data to preserve the model's knowledge, we employ knowledge distillation methods to maintain the performance of the infected model on benign samples, and introduce a parameter importance evaluation mechanism based on elastic weight constraints to facilitate the fine-tuning of the infected model. The effectiveness, practicality, and stealthiness of the proposed attack are comprehensively evaluated on three real-world datasets. Furthermore, we explore the potential for enhancing the attack through the use of auxiliary datasets and model inversion.
format Preprint
id arxiv_https___arxiv_org_abs_2408_11444
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle A Practical Trigger-Free Backdoor Attack on Neural Networks
Wang, Jiahao
Zhang, Xianglong
Cheng, Xiuzhen
Hu, Pengfei
Zhang, Guoming
Cryptography and Security
Backdoor attacks on deep neural networks have emerged as significant security threats, especially as DNNs are increasingly deployed in security-critical applications. However, most existing works assume that the attacker has access to the original training data. This limitation restricts the practicality of launching such attacks in real-world scenarios. Additionally, using a specified trigger to activate the injected backdoor compromises the stealthiness of the attacks. To address these concerns, we propose a trigger-free backdoor attack that does not require access to any training data. Specifically, we design a novel fine-tuning approach that incorporates the concept of malicious data into the concept of the attacker-specified class, resulting the misclassification of trigger-free malicious data into the attacker-specified class. Furthermore, instead of relying on training data to preserve the model's knowledge, we employ knowledge distillation methods to maintain the performance of the infected model on benign samples, and introduce a parameter importance evaluation mechanism based on elastic weight constraints to facilitate the fine-tuning of the infected model. The effectiveness, practicality, and stealthiness of the proposed attack are comprehensively evaluated on three real-world datasets. Furthermore, we explore the potential for enhancing the attack through the use of auxiliary datasets and model inversion.
title A Practical Trigger-Free Backdoor Attack on Neural Networks
topic Cryptography and Security
url https://arxiv.org/abs/2408.11444