TY - GEN
T1 - OrdinalNet - Dynamic and Robust Backdoor Attacks
AU - Ma, Xinrui
AU - Gui, Zhiming
AU - Lu, Yunfeng
N1 - Publisher Copyright:
© 2023 IEEE.
PY - 2023
Y1 - 2023
N2 - DNN are vulnerable to backdoor attacks that can manipulate their outputs, leading to incorrect results. We point out the limitations of current backdoor attack methods, which rely on static and fixed triggers, making them easily detectable by existing backdoor defenses. In response, we propose a novel backdoor attack approach based on image features. This method leverages image to create an ordinal network that captures the precise image structure. Triggers are then generated using the information from this ordinal network. Additionally, we introduce a regularization method to enhance the robustness of our backdoor attack method against model diagnose-based defences. Our experimental results demonstrate the effectiveness of our approach. When compared to traditional backdoor attack methods such as BadNet and Blend, our method achieves attack success rate exceeding 99% on datasets like CIFAR-10, Tiny-ImageNet, and CelebA. Notably, the accuracy on clean samples only experiences a marginal decrease of less than 1%. Furthermore, our approach showcases its generalizability across different neural network architectures.
AB - DNN are vulnerable to backdoor attacks that can manipulate their outputs, leading to incorrect results. We point out the limitations of current backdoor attack methods, which rely on static and fixed triggers, making them easily detectable by existing backdoor defenses. In response, we propose a novel backdoor attack approach based on image features. This method leverages image to create an ordinal network that captures the precise image structure. Triggers are then generated using the information from this ordinal network. Additionally, we introduce a regularization method to enhance the robustness of our backdoor attack method against model diagnose-based defences. Our experimental results demonstrate the effectiveness of our approach. When compared to traditional backdoor attack methods such as BadNet and Blend, our method achieves attack success rate exceeding 99% on datasets like CIFAR-10, Tiny-ImageNet, and CelebA. Notably, the accuracy on clean samples only experiences a marginal decrease of less than 1%. Furthermore, our approach showcases its generalizability across different neural network architectures.
KW - Backdoor Attack
KW - DNN
KW - image classification
KW - ordinal network
UR - https://www.scopus.com/pages/publications/85178614601
U2 - 10.1109/ICSESS58500.2023.10293062
DO - 10.1109/ICSESS58500.2023.10293062
M3 - 会议稿件
AN - SCOPUS:85178614601
T3 - Proceedings of the IEEE International Conference on Software Engineering and Service Sciences, ICSESS
SP - 141
EP - 144
BT - ICSESS 2023 - Proceedings of 2023 IEEE 14th International Conference on Software Engineering and Service Science
A2 - Wenzheng, Li
PB - IEEE Computer Society
T2 - 14th IEEE International Conference on Software Engineering and Service Science, ICSESS 2023
Y2 - 17 October 2023 through 18 October 2023
ER -