Geometry-Aware Backdoor Attacks: Leveraging Curvature in Hyperbolic Embeddings

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteur principal: Baheri, Ali
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866911197139304448
author Baheri, Ali
author_facet Baheri, Ali
contents Non-Euclidean foundation models increasingly place representations in curved spaces such as hyperbolic geometry. We show that this geometry creates a boundary-driven asymmetry that backdoor triggers can exploit. Near the boundary, small input changes appear subtle to standard input-space detectors but produce disproportionately large shifts in the model's representation space. Our analysis formalizes this effect and also reveals a limitation for defenses: methods that act by pulling points inward along the radius can suppress such triggers, but only by sacrificing useful model sensitivity in that same direction. Building on these insights, we propose a simple geometry-adaptive trigger and evaluate it across tasks and architectures. Empirically, attack success increases toward the boundary, whereas conventional detectors weaken, mirroring the theoretical trends. Together, these results surface a geometry-specific vulnerability in non-Euclidean models and offer analysis-backed guidance for designing and understanding the limits of defenses.
format Preprint
id arxiv_https___arxiv_org_abs_2510_06397
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Geometry-Aware Backdoor Attacks: Leveraging Curvature in Hyperbolic Embeddings
Baheri, Ali
Machine Learning
Artificial Intelligence
Non-Euclidean foundation models increasingly place representations in curved spaces such as hyperbolic geometry. We show that this geometry creates a boundary-driven asymmetry that backdoor triggers can exploit. Near the boundary, small input changes appear subtle to standard input-space detectors but produce disproportionately large shifts in the model's representation space. Our analysis formalizes this effect and also reveals a limitation for defenses: methods that act by pulling points inward along the radius can suppress such triggers, but only by sacrificing useful model sensitivity in that same direction. Building on these insights, we propose a simple geometry-adaptive trigger and evaluate it across tasks and architectures. Empirically, attack success increases toward the boundary, whereas conventional detectors weaken, mirroring the theoretical trends. Together, these results surface a geometry-specific vulnerability in non-Euclidean models and offer analysis-backed guidance for designing and understanding the limits of defenses.
title Geometry-Aware Backdoor Attacks: Leveraging Curvature in Hyperbolic Embeddings
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2510.06397