Return
WPDA: Frequency-based Backdoor Attack with Wavelet Packet Decomposition
DOI:10.1016/j.neunet.2025.108074.png)
Abstract
En 中文
• Currently, existing backdoor attacks often require moderate or high poisoning ratios to achieve the desired attack performance, but making them susceptible to some advanced backdoor defenses (e.g., poisoned sample detection). One possible solution to this dilemma is enhancing the attack performance at low poisoning ratios, which has been rarely studied due to its high challenge. In this work, we develop an an innovative backdoor attack method (i.e., WPDA), which achieves a 98.12 2 poisoned samples among 50,000 training samples. • We leverage WPD to demonstrate the learning mechanism of DNNs in the frequency domain, and propose an effective approach to identify the most critical frequency regions that could be sufficiently learned by the DNN model. • Different from existing backdoor attacks in frequency domain, i.e., injecting trigger information into fixed frequency regions, which results in suboptimal performance, we consider the difference among datasets and propose a dataset-specific poisoning regions selection strategy for backdoor attacks. Highlights (for review)
Journal
IF:
6.3
Papers:
7.8K
Citations:
3.0W

