跳到主要导航 跳到搜索 跳到主要内容

无需触发器与辅助数据集的模型后门攻击

  • Jiahao Wang
  • , Xianglong Zhang
  • , Huanle Zhang
  • , Xiaobo Ma
  • , Xiuzhen Cheng
  • , Pengfei Hu
  • , Guoming Zhang
  • Shandong University

科研成果: 期刊稿件文章同行评审

摘要

With the rapid deployment of deep neural networks (DNNs) across critical application domains, backdoor attacks have emerged as a significant security threat. However, most existing methods rely on access to the target model's original training data and require explicit triggers to activate malicious behavior, which limits their practicality and compromises stealth.This paper proposes a novel trigger-free and data-free backdoor attack framework that enhances both the practicality and concealment of attacks. Our approach leverages a fine-tuning strategy to embed the semantics of malicious data into the feature space of an attacker-specified target class, enabling adversarial samples to be misclassified consistently without any visible trigger.To preserve the model's performance on clean inputs, we incorporate a knowledge distillation mechanism in place of the original training data and design an elastic weight consolidation-based parameter importance estimation method to guide the injection process.Extensive experiments conducted on three real-world benchmark datasets demonstrate the effectiveness, stealthiness, and real-world feasibility of the proposed method. Additionally, we explore the potential of auxiliary data and model inversion techniques in further enhancing attack success.

投稿的翻译标题Trigger-free and data-free backdoor attacks on deep neural networks
源语言繁体中文
页(从-至)2798-2816
页数19
期刊Scientia Sinica Informationis
55
11
DOI
出版状态已出版 - 1 11月 2025

关键词

  • backdoor attack
  • data-free attack
  • machine learning security
  • trigger-free attack

学术指纹

探究 '无需触发器与辅助数据集的模型后门攻击' 的科研主题。它们共同构成独一无二的学术指纹。

引用此