跳到主要导航 跳到搜索 跳到主要内容

OrdinalNet - Dynamic and Robust Backdoor Attacks

  • Beijing University of Technology

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

DNN are vulnerable to backdoor attacks that can manipulate their outputs, leading to incorrect results. We point out the limitations of current backdoor attack methods, which rely on static and fixed triggers, making them easily detectable by existing backdoor defenses. In response, we propose a novel backdoor attack approach based on image features. This method leverages image to create an ordinal network that captures the precise image structure. Triggers are then generated using the information from this ordinal network. Additionally, we introduce a regularization method to enhance the robustness of our backdoor attack method against model diagnose-based defences. Our experimental results demonstrate the effectiveness of our approach. When compared to traditional backdoor attack methods such as BadNet and Blend, our method achieves attack success rate exceeding 99% on datasets like CIFAR-10, Tiny-ImageNet, and CelebA. Notably, the accuracy on clean samples only experiences a marginal decrease of less than 1%. Furthermore, our approach showcases its generalizability across different neural network architectures.

源语言英语
主期刊名ICSESS 2023 - Proceedings of 2023 IEEE 14th International Conference on Software Engineering and Service Science
编辑Li Wenzheng
出版商IEEE Computer Society
141-144
页数4
ISBN(电子版)9798350336269
DOI
出版状态已出版 - 2023
活动14th IEEE International Conference on Software Engineering and Service Science, ICSESS 2023 - Beijing, 中国
期限: 17 10月 202318 10月 2023

出版系列

姓名Proceedings of the IEEE International Conference on Software Engineering and Service Sciences, ICSESS
ISSN(印刷版)2327-0586
ISSN(电子版)2327-0594

会议

会议14th IEEE International Conference on Software Engineering and Service Science, ICSESS 2023
国家/地区中国
Beijing
时期17/10/2318/10/23

学术指纹

探究 'OrdinalNet - Dynamic and Robust Backdoor Attacks' 的科研主题。它们共同构成独一无二的学术指纹。

引用此