Skip to main navigation Skip to search Skip to main content

OrdinalNet - Dynamic and Robust Backdoor Attacks

  • Beijing University of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

DNN are vulnerable to backdoor attacks that can manipulate their outputs, leading to incorrect results. We point out the limitations of current backdoor attack methods, which rely on static and fixed triggers, making them easily detectable by existing backdoor defenses. In response, we propose a novel backdoor attack approach based on image features. This method leverages image to create an ordinal network that captures the precise image structure. Triggers are then generated using the information from this ordinal network. Additionally, we introduce a regularization method to enhance the robustness of our backdoor attack method against model diagnose-based defences. Our experimental results demonstrate the effectiveness of our approach. When compared to traditional backdoor attack methods such as BadNet and Blend, our method achieves attack success rate exceeding 99% on datasets like CIFAR-10, Tiny-ImageNet, and CelebA. Notably, the accuracy on clean samples only experiences a marginal decrease of less than 1%. Furthermore, our approach showcases its generalizability across different neural network architectures.

Original languageEnglish
Title of host publicationICSESS 2023 - Proceedings of 2023 IEEE 14th International Conference on Software Engineering and Service Science
EditorsLi Wenzheng
PublisherIEEE Computer Society
Pages141-144
Number of pages4
ISBN (Electronic)9798350336269
DOIs
StatePublished - 2023
Event14th IEEE International Conference on Software Engineering and Service Science, ICSESS 2023 - Beijing, China
Duration: 17 Oct 202318 Oct 2023

Publication series

NameProceedings of the IEEE International Conference on Software Engineering and Service Sciences, ICSESS
ISSN (Print)2327-0586
ISSN (Electronic)2327-0594

Conference

Conference14th IEEE International Conference on Software Engineering and Service Science, ICSESS 2023
Country/TerritoryChina
CityBeijing
Period17/10/2318/10/23

Keywords

  • Backdoor Attack
  • DNN
  • image classification
  • ordinal network

Fingerprint

Dive into the research topics of 'OrdinalNet - Dynamic and Robust Backdoor Attacks'. Together they form a unique fingerprint.

Cite this