arrow
Return

Stealthy Backdoors as Compression Artifacts

delete2022-01-01
delete11
delete
OA
AI
Y
Yulong Tian
F
Fnu Suya
F
Fengyuan Xu
D
David Evans *
DOI:10.1109/TIFS.2022.3160359delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Model compression is a widely-used approach for reducing the size of deep learning models without much accuracy loss, enabling resource-hungry models to be compressed for use on resource-constrained devices. In this paper, we study the risk that model compression could provide an opportunity for adversaries to inject stealthy backdoors. In a backdoor attack on a machine learning model, an adversary produces a model that performs well on normal inputs but outputs targeted misclassifications on inputs containing a small trigger pattern. We design stealthy backdoor attacks such that the full-sized model released by adversaries appears to be free from backdoors (even when tested using state-of-the-art techniques), but when the model is compressed it exhibits a highly effective backdoor. We show this can be done for two common model compression techniques-model pruning and model quantization-even in settings where the adversary has limited knowledge of how the particular compression will be done. Our findings demonstrate the importance of performing security tests on the models that will actually be deployed not in their precompressed version. Our implementation is available at https://github.com/yulongtzzz/Stealthy-Backdoors-as-Compression-Artifacts.
Keywords:
Computational modeling
Quantization (signal)
Security
Numerical models
Deep learning
Data models
Training
Deep learning
neural network compression
backdoor attack

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

U
University of Virginia
Scholars:
3.0W
Papers: 2.7W
Citations: 4.1W
N
nanjing university
Scholars:
7.8W
Papers: 5.6W
Citations: 87