Return
A trigger-perceivable backdoor attack framework driven by image steganography
DOI:10.1016/j.patcog.2024.111262.png)
Abstract
En 中文
As deep network models have developed rapidly in the past decades, studying their vulnerability with backdoor attacks is essential towards building robust models in practical scenarios. To launch effective backdoor attack, the core is enabling the victim model to perceive the trigger for making wrong predictions. However, in the existing methods, the attackers inject trigger without considering whether such trigger can be perceived by the victim model. Therefore, the potential of backdoor attacks may not be fully exploited. To address the issues, this paper proposes a backdoor attack framework called Steganography-Driven B ackdoor Attack (SDriBA). Its key is to formulate trigger injection and perception under backdoor attack into message hiding and extraction under steganography. Specifically, an invertible neural network (INN) equipped with a transformation layer is applied. The forward calculation of INN takes in the clean image and trigger image and then generates the poisoned image, while the reverse calculation receives the poisoned image and the randomly sampled latent noise and outputs the recovered clean image and recovered trigger image. Owing to the optimization paradigm of steganography and the reversibility of INN, the recovered trigger and the original trigger is of high similarity. In such a manner, trigger can be injected in a model-perceivable manner. Experimental results show that the proposed SDriBA can achieve satisfying attack performance under data transformations and against mainstream backdoor defense methods.
Keywords:
Backdoor attack
Image steganography
Data transformation
Perceivability
Robustness
Journal
IF:
7.6
Papers:
1.3W
Citations:
4.5W
Organization
No organization information available

