arrow
Return

WPDA: Frequency-based Backdoor Attack with Wavelet Packet Decomposition

delete2025-09-04
delete0
PRE
AI
Z
Zhengyao Song
Y
Yongqiang Li
袁丹妮 cover
袁丹妮 (Danni Yuan)
L
Li Liu
S
Shaokui Wei
B
Baoyuan Wu
DOI:10.1016/j.neunet.2025.108074delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
• Currently, existing backdoor attacks often require moderate or high poisoning ratios to achieve the desired attack performance, but making them susceptible to some advanced backdoor defenses (e.g., poisoned sample detection). One possible solution to this dilemma is enhancing the attack performance at low poisoning ratios, which has been rarely studied due to its high challenge. In this work, we develop an an innovative backdoor attack method (i.e., WPDA), which achieves a 98.12 2 poisoned samples among 50,000 training samples. • We leverage WPD to demonstrate the learning mechanism of DNNs in the frequency domain, and propose an effective approach to identify the most critical frequency regions that could be sufficiently learned by the DNN model. • Different from existing backdoor attacks in frequency domain, i.e., injecting trigger information into fixed frequency regions, which results in suboptimal performance, we consider the difference among datasets and propose a dataset-specific poisoning regions selection strategy for backdoor attacks. Highlights (for review)

Journal

Neural Networks cover
Neural Networks
IF:
6.3
Papers:
7.8K
Citations:
3.0W

Organization

T
The Chinese University of Hong Kong
Scholars:
3.8K
Papers: 1.9K
Citations: 3
H
harbin institute of technology
Scholars:
8.0W
Papers: 6.6W
Citations: 66