Return
Boosting backdoor attack with a learnable poisoning sample selection strategy
DOI:10.1016/j.neucom.2026.134024.png)
Abstract
En 中文
• A learnable sample selection strategy (LPS) is proposed to boost data-poisoning backdoor attacks. Addressing the randomness in existing attack sample selection, we introduce LPS to select the most impactful samples for backdoor injection from a global perspective. • The sample selection task is formulated as a min-max adversarial optimization problem. We use a learnable binary mask to transform sample selection into a min-max problem, where the inner maximization finds “hard” samples to hinder training, while the outer minimization trains a surrogate model to select the most effective samples via adversarial learning. • LPS significantly boosts the performance and efficiency of various backdoor attacks. Compared to random selection and the SOTA FUS strategy, experiments show LPS significantly improves attack success rates for classic attacks ( , BadNets, Blended) and reduces computation time by about 82 %. • LPS-boosted attacks show stronger robustness against mainstream defense methods. We provide a mechanistic explanation rooted in feature-space dispersion and training-loss dynamics that clarifies why hard-sample selection inherently impedes backdoor detection. • LPS generalizes across CNN and ViT architectures and remains effective under non-IID data distributions. Experiments with DeiT-Small and cross-architecture settings confirm broad applicability, and non-IID analyses with Dirichlet-distributed data validate robustness under realistic deployment conditions.
Keywords:
Learnable Sample Selection
Backdoor Attack
Data Poisoning
Adversarial Optimization
Model Robustness
Journal
IF:
6.5
Papers:
2.5W
Citations:
6.5W

