摘要
With the rapid deployment of deep neural networks (DNNs) across critical application domains, backdoor attacks have emerged as a significant security threat. However, most existing methods rely on access to the target model's original training data and require explicit triggers to activate malicious behavior, which limits their practicality and compromises stealth.This paper proposes a novel trigger-free and data-free backdoor attack framework that enhances both the practicality and concealment of attacks. Our approach leverages a fine-tuning strategy to embed the semantics of malicious data into the feature space of an attacker-specified target class, enabling adversarial samples to be misclassified consistently without any visible trigger.To preserve the model's performance on clean inputs, we incorporate a knowledge distillation mechanism in place of the original training data and design an elastic weight consolidation-based parameter importance estimation method to guide the injection process.Extensive experiments conducted on three real-world benchmark datasets demonstrate the effectiveness, stealthiness, and real-world feasibility of the proposed method. Additionally, we explore the potential of auxiliary data and model inversion techniques in further enhancing attack success.
| 投稿的翻译标题 | Trigger-free and data-free backdoor attacks on deep neural networks |
|---|---|
| 源语言 | 繁体中文 |
| 页(从-至) | 2798-2816 |
| 页数 | 19 |
| 期刊 | Scientia Sinica Informationis |
| 卷 | 55 |
| 期 | 11 |
| DOI | |
| 出版状态 | 已出版 - 1 11月 2025 |
关键词
- backdoor attack
- data-free attack
- machine learning security
- trigger-free attack
学术指纹
探究 '无需触发器与辅助数据集的模型后门攻击' 的科研主题。它们共同构成独一无二的学术指纹。引用此
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver