arrow
Return

KerbNet : A QoE-Aware Kernel-Based Backdoor Attack Framework

delete2024-07-01
delete2
PRE
AI
X
Xueluan Gong
陈彦交 cover
陈彦交 (Yanjiao Chen) *
H
Huayang Huang
W
Weihan Kong
Z
Ziyao Wang
C
Chao Shen
王茜 cover
王茜 (Qian Wang) *
DOI:10.1109/TDSC.2023.3286842delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Deep neural networks are vulnerable to backdoor attacks, where a specially-designed trigger will lead to misclassification of any benign samples. However, existing backdoor attacks usually impose conspicuous patch triggers on images, which are easily detected by humans and defense algorithms. Existing works on invisible triggers, however, either have reduced attack success rate or yield detectable patterns to visual inspections. In this article, we propose KerbNet, a kernel-based backdoor attack framework, which applies kernel operations to clean samples as the trigger to incur misclassification. The kernel-processed samples achieve a high attack success rate while appearing natural with high Quality-of-Experience (QoE). We carefully design the kernel trigger generation algorithm by exploiting the neural network structure to propagate the influence of the trigger to the target misclassification label under the QoE constraint. We conduct extensive experiments on five datasets, i.e., MNIST, GTSRB, CIFAR-10, CelebA, and ImageNette to evaluate the effectiveness and practicality of KerbNet under the impact of various factors, including neuron-residing layer, kernel size, base image, loss function, model structure, and so on. We also show that our proposed attacks can evade state-of-the-art defense strategies and visual inspections. Code will be available after publication.
Keywords:
Kernel
Inspection
Visualization
Quality of experience
Training
Biological neural networks
Smoothing methods
Deep neural network
backdoor attack
quality-of-experience
kernel algorithm

Journal

IEEE Transactions on Dependable and Secure Computing cover
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
Papers:
2.4K
Citations:
9.6K

Organization

X
xi'an jiaotong university
Scholars:
9.2W
Papers: 6.6W
Citations: 75
W
wuhan university
Scholars:
8.0W
Papers: 5.8W
Citations: 70
Z
zhejiang university
Scholars:
17.5W
Papers: 12.0W
Citations: 152
researcher View more organizations