arrow
Return

BATG: A Backdoor Attack Method Based on Trigger Generation

delete2024-12-21
delete0
delete
OA
AI
W
Weixuan Tang
X
Xie, Haoke
Y
Yuan Rao *
龙敏 (Min Long) *
Q
Qi Tao
周支立 cover
周支立 (Zhili Zhou)
DOI:10.3390/electronics13245031delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Backdoor attacks aim to implant hidden backdoors into Deep Neural Networks (DNNs) so that the victim models perform well on clean images, whereas their predictions would be maliciously changed on poisoned images. However, most existing backdoor attacks lack the invisibility and robustness required for real-world applications, especially when it comes to resisting image compression techniques, such as JPEG and WEBP. To address these issues, in this paper, we propose a Backdoor Attack Method based on Trigger Generation (BATG). Specifically, a deep convolutional generative network is utilized as the trigger generation model to generate effective trigger images and an Invertible Neural Network (INN) is utilized as the trigger injection model to embed the generated trigger images into clean images to create poisoned images. Furthermore, a noise layer is used to simulate image compression attacks for adversarial training, enhancing the robustness against real-world image compression. Comprehensive experiments on benchmark datasets demonstrate the effectiveness, invisibility, and robustness of the proposed BATG.
Keywords:
backdoor attack
invertible neural network
trigger generation

Journal

Electronics cover
Electronics
IF:
2.6
Papers:
9.3K
Citations:
4.7W

Organization

B
Beijing Univ Posts and Telecommun
Scholars:
719
Papers: 311
Citations: 55