Return
GhostBackdoor: A Resistant Backdoor Attack
DOI:10.1109/JIOT.2026.3680800.png)
Abstract
En 中文
The robustness, security, and safety of artificial intelligence (AI) systems have become growing concerns, particularly as deep learning (DL) models are increasingly deployed in critical applications. Among emerging threats, backdoor attacks pose a serious risk by embedding hidden malicious behaviors into otherwise well-performing models. Although recent advances in detection techniques have improved defenses for computer vision systems, our findings demonstrate that even simple but carefully designed poisoning strategies can successfully evade these defenses. In this article, we introduce GhostBackdoor, a novel backdoored model trained using a custom loss function and targeted data augmentation. The proposed loss function aligns neuron activations between clean and poisoned inputs, effectively masking activation anomalies, while the augmentation enforces strict location- and pattern-specific triggers that activate the backdoor only under specific conditions. After training, the model maintains behavior indistinguishable from a clean model unless exposed to the designated trigger with the specific pattern and at the designed locations. We evaluate GhostBackdoor against a broad range of leading defense mechanisms, most of which fail to detect the implanted backdoor. Our results highlight how the vast hypothesis space of DL models can be exploited to conceal malicious activations, underscoring the need for more robust security strategies in AI-driven systems, including those used in Internet of Things (IoT) applications.
Keywords:
Adversarial robustness
backdoor attacks
deep learning (DL)
Internet of Things (IoT)
model security
secure artificial intelligence (AI) systems
Journal
IF:
8.9
Papers:
1.4W
Citations:
7.8W

