Dispersed Pixel Perturbation-based Imperceptible Backdoor Trigger for Image Classifier Models
Wang, Yulong, Zhao, Minghui, Li, Shenghong, Yuan, Xin, Ni, Wei
–arXiv.org Artificial Intelligence
Typical deep neural network (DNN) backdoor attacks are based on triggers embedded in inputs. Existing imperceptible triggers are computationally expensive or low in attack success. In this paper, we propose a new backdoor trigger, which is easy to generate, imperceptible, and highly effective. The new trigger is a uniformly randomly generated three-dimensional (3D) binary pattern that can be horizontally and/or vertically repeated and mirrored and superposed onto three-channel images for training a backdoored DNN model. Dispersed throughout an image, the new trigger produces weak perturbation to individual pixels, but collectively holds a strong recognizable pattern to train and activate the backdoor of the DNN. We also analytically reveal that the trigger is increasingly effective with the improving resolution of the images. Experiments are conducted using the ResNet-18 and MLP models on the MNIST, CIFAR-10, and BTSR datasets. In terms of imperceptibility, the new trigger outperforms existing triggers, such as BadNets, Trojaned NN, and Hidden Backdoor, by over an order of magnitude. The new trigger achieves an almost 100% attack success rate, only reduces the classification accuracy by less than 0.7%-2.4%, and invalidates the state-of-the-art defense techniques.
arXiv.org Artificial Intelligence
Aug-19-2022
- Country:
- Oceania > Australia
- New South Wales > Sydney (0.14)
- North America
- United States
- Washington > King County
- Seattle (0.04)
- Utah > Salt Lake County
- Salt Lake City (0.04)
- Texas > Travis County
- Austin (0.04)
- New York > New York County
- New York City (0.04)
- Nevada > Clark County
- Las Vegas (0.04)
- Louisiana > Orleans Parish
- New Orleans (0.04)
- Hawaii > Honolulu County
- Honolulu (0.04)
- California
- San Francisco County > San Francisco (0.14)
- San Diego County > San Diego (0.04)
- Santa Clara County > San Jose (0.04)
- Washington > King County
- Puerto Rico > San Juan
- San Juan (0.04)
- Canada
- Quebec > Montreal (0.04)
- British Columbia > Metro Vancouver Regional District
- Vancouver (0.04)
- United States
- Europe
- Asia > China
- Beijing > Beijing (0.04)
- Shanghai > Shanghai (0.04)
- Jiangsu Province > Nanjing (0.04)
- Hong Kong (0.04)
- Shanxi Province (0.04)
- Shaanxi Province > Xi'an (0.04)
- Oceania > Australia
- Genre:
- Research Report (0.63)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology: