arrow
Return

QuEST: Quantization-Conditioned Efficient Stealthy Trojan

delete2026-03-05
delete0
PRE
AI
L
Liming Lu
S
Shuchao Pang
J
Jiakai Wang
X
Xiang Gu
刘云淮 cover
刘云淮 (Yunhuai Liu)
X
Xianglong Liu
Y
Yongbin Zhou
DOI:10.1109/TIFS.2026.3671079delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Quantization-conditioned backdoor attacks, which exploit model quantization states to trigger malicious behavior, pose a hidden threat to deep learning security. However, current studies ignore the feasibility of attacks, i.e., detection visibility, and computational overhead, leading to significant constraints on their practical deployment in real-world adversarial scenarios. To address these limitations, we propose Quantization-conditioned Efficient Stealthy Trojan (QuEST), a novel framework that enhances both the stealth and efficiency of backdoor attacks under quantization constraints. For enhancing stealthiness, we design a stealth-optimized training scheme that benefits from the parametric backdoor injection and trigger scaling augmentation to maintain the consistency of model behavior during attack. In this way, the defender will fail to capture the suspicious behavior differences for detection due to the made efforts in both model-side and data-side. To improve efficiency, we introduce information-guided parameter sharing, which utilizes parameter redundancy analysis and Fisher divergence metrics to identify a minimal amount of quantization-preserved parameters for backdoor injection. These parameters are strategically shared between the malicious and benign models, enabling concurrent training and substantially reducing overall training time. Extensive experiments demonstrate that QuEST maintains competitive attack success rates while improving stealth performance by 18.75% and reducing computational costs by 26.66% on average compared to state-of-the-art methods, highlighting QuEST’s potential for more practical adversarial deployments in real-world scenarios. Our code is available here.
Keywords:
Backdoor attacks
model quantization
deep learning security
stealthy Trojan

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

Z
zhongguancun laboratory
Scholars:
46
Papers: 25
Citations: 0
B
beihang university
Scholars:
5.2K
Papers: 2.0K
Citations: 21
N
nanjing university of science and technology
Scholars:
3.4K
Papers: 1.1K
Citations: 0
P
peking university
Scholars:
11.7W
Papers: 8.7W
Citations: 146
researcher View more organizations