arrow
返回

Enhancing Backdoor Attacks With Multi-Level MMD Regularization

delete2023-03-01
delete5
delete
OA
AI
P
Pengfei Xia
H
Hongjing Niu
Z
Ziqiang Li
李
李斌 (Bin Li) *
DOI:10.1109/TDSC.2022.3161477delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
While Deep Neural Networks (DNNs) excel in many tasks, the huge training resources they require become an obstacle for practitioners to develop their own models. It has become common to collect data from the Internet or hire a third party to train models. Unfortunately, recent studies have shown that these operations provide a viable pathway for maliciously injecting hidden backdoors into DNNs. Several defense methods have been developed to detect malicious samples, with the common assumption that the latent representations of benign and malicious samples extracted by the infected model exhibit different distributions. However, it is still an open question whether this assumption holds up. In this article, we investigate such differences thoroughly via answering three questions: 1) What are the characteristics of the distributional differences? 2) How can they be effectively reduced? 3) What impact does this reduction have on difference-based defense methods? First, the distributional differences of multi-level representations on the regularly trained backdoored models are verified to be significant by adopting Maximum Mean Discrepancy (MMD), Energy Distance (ED), and Sliced Wasserstein Distance (SWD) as the metrics. Then, ML-MMDR, a difference reduction method that adds multi-level MMD regularization into the loss, is proposed, and its effectiveness is testified on three typical difference-based defense methods. Across all the experimental settings, the F1 scores of these methods drop from 90%-100% on the regularly trained backdoored models to 60%-70% on the models trained with ML-MMDR. These results indicate that the proposed MMD regularization can enhance the stealthiness of existing backdoor attack methods. The prototype code of our method is now available at https://github.com/xpf/Multi-Level-MMD-Regularization.
Keyword:
Biological system modeling
Training
Computational modeling
Data models
Neural networks
Mathematical models
Costs
Deep neural networks
backdoor attacks
distributional differences
maximum mean discrepancy

期刊

IEEE Transactions on Dependable and Secure Computing 封面图
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
论文数:
2.5K
被引数:
9.6K

机构

U
university of science & technology of china, cas
学者数:
3.2W
论文数: 2.7W
被引数: 74
C
chinese academy of sciences
学者数:
56.7W
论文数: 45.0W
被引数: 704
引用论文

引用论文

Glycan shield and fusion activation of a deltacoronavirus spike glycoprotein fine-tuned for enteric infections
err
IF0
err2017-11-22
err0
PREAI
errX. Xiong; M.A. Tortorici; S. Snijder; C. Yoshioka; A.C. Walls; W. Li; A.T. McGuire; F.A. Rey; B.J. Bosch; D. Veesler
err分享
err收藏
err分享
err收藏
Experimental demonstration of composite stimulated Raman adiabatic passage
err2018-11-13
err0
errOAAI
errAlexander Bruns; Genko T. Genov; Marcel Hain; Nikolay V. Vitanov; Thomas Halfmann
err分享
err收藏
Monitoring of Water Transportation in Plant Stem With Microneedle Sap Flow Sensor
err2018-06-01
err0
PREAI
errSangwoong Baek; Eunyong Jeon; Kyoung Sub Park; Kyung-Hwan Yeo; Junghoon Lee
err分享
err收藏
err分享
err收藏
err
IF0
err
err0
errOAAI
err
err分享
err收藏
学者 查看更多内容