The Ripple Effect: On Unforeseen Complications of Backdoor Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Rui, Shen, Yun, Li, Hongwei, Jiang, Wenbo, Chen, Hanxiao, Zhang, Yuan, Xu, Guowen, Zhang, Yang
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913844072284160
author Zhang, Rui
Shen, Yun
Li, Hongwei
Jiang, Wenbo
Chen, Hanxiao
Zhang, Yuan
Xu, Guowen
Zhang, Yang
author_facet Zhang, Rui
Shen, Yun
Li, Hongwei
Jiang, Wenbo
Chen, Hanxiao
Zhang, Yuan
Xu, Guowen
Zhang, Yang
contents Recent research highlights concerns about the trustworthiness of third-party Pre-Trained Language Models (PTLMs) due to potential backdoor attacks. These backdoored PTLMs, however, are effective only for specific pre-defined downstream tasks. In reality, these PTLMs can be adapted to many other unrelated downstream tasks. Such adaptation may lead to unforeseen consequences in downstream model outputs, consequently raising user suspicion and compromising attack stealthiness. We refer to this phenomenon as backdoor complications. In this paper, we undertake the first comprehensive quantification of backdoor complications. Through extensive experiments using 4 prominent PTLMs and 16 text classification benchmark datasets, we demonstrate the widespread presence of backdoor complications in downstream models fine-tuned from backdoored PTLMs. The output distribution of triggered samples significantly deviates from that of clean samples. Consequently, we propose a backdoor complication reduction method leveraging multi-task learning to mitigate complications without prior knowledge of downstream tasks. The experimental results demonstrate that our proposed method can effectively reduce complications while maintaining the efficacy and consistency of backdoor attacks. Our code is available at https://github.com/zhangrui4041/Backdoor_Complications.
format Preprint
id arxiv_https___arxiv_org_abs_2505_11586
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle The Ripple Effect: On Unforeseen Complications of Backdoor Attacks
Zhang, Rui
Shen, Yun
Li, Hongwei
Jiang, Wenbo
Chen, Hanxiao
Zhang, Yuan
Xu, Guowen
Zhang, Yang
Cryptography and Security
Artificial Intelligence
Recent research highlights concerns about the trustworthiness of third-party Pre-Trained Language Models (PTLMs) due to potential backdoor attacks. These backdoored PTLMs, however, are effective only for specific pre-defined downstream tasks. In reality, these PTLMs can be adapted to many other unrelated downstream tasks. Such adaptation may lead to unforeseen consequences in downstream model outputs, consequently raising user suspicion and compromising attack stealthiness. We refer to this phenomenon as backdoor complications. In this paper, we undertake the first comprehensive quantification of backdoor complications. Through extensive experiments using 4 prominent PTLMs and 16 text classification benchmark datasets, we demonstrate the widespread presence of backdoor complications in downstream models fine-tuned from backdoored PTLMs. The output distribution of triggered samples significantly deviates from that of clean samples. Consequently, we propose a backdoor complication reduction method leveraging multi-task learning to mitigate complications without prior knowledge of downstream tasks. The experimental results demonstrate that our proposed method can effectively reduce complications while maintaining the efficacy and consistency of backdoor attacks. Our code is available at https://github.com/zhangrui4041/Backdoor_Complications.
title The Ripple Effect: On Unforeseen Complications of Backdoor Attacks
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2505.11586