Backdoor Attacks Against Incremental Learners: An Empirical Evaluation Study

05/28/2023
by   Yiqi Zhong, et al.
0

Large amounts of incremental learning algorithms have been proposed to alleviate the catastrophic forgetting issue arises while dealing with sequential data on a time series. However, the adversarial robustness of incremental learners has not been widely verified, leaving potential security risks. Specifically, for poisoning-based backdoor attacks, we argue that the nature of streaming data in IL provides great convenience to the adversary by creating the possibility of distributed and cross-task attacks – an adversary can affect any unknown previous or subsequent task by data poisoning at any time or time series with extremely small amount of backdoor samples injected (e.g., 0.1% based on our observations). To attract the attention of the research community, in this paper, we empirically reveal the high vulnerability of 11 typical incremental learners against poisoning-based backdoor attack on 3 learning scenarios, especially the cross-task generalization effect of backdoor knowledge, while the poison ratios range from 5% to as low as 0.1%. Finally, the defense mechanism based on activation clustering is found to be effective in detecting our trigger pattern to mitigate potential security risks.

READ FULL TEXT

page 2

page 6

research
02/17/2020

Targeted Forgetting and False Memory Formation in Continual Learners through Adversarial Backdoor Attacks

Artificial neural networks are well-known to be susceptible to catastrop...
research
07/11/2022

Susceptibility of Continual Learning Against Adversarial Attacks

The recent advances in continual (incremental or lifelong) learning have...
research
02/09/2022

False Memory Formation in Continual Learners Through Imperceptible Backdoor Trigger

In this brief, we show that sequentially learning new information presen...
research
02/16/2021

Adversarial Targeted Forgetting in Regularization and Generative Based Continual Learning Models

Continual (or "incremental") learning approaches are employed when addit...
research
09/04/2019

Lifelong Machine Learning with Deep Streaming Linear Discriminant Analysis

When a robot acquires new information, ideally it would immediately be c...
research
01/07/2022

Detecting CAN Masquerade Attacks with Signal Clustering Similarity

Vehicular Controller Area Networks (CANs) are susceptible to cyber attac...
research
08/17/2021

Incremental cluster validity index-guided online learning for performance and robustness to presentation order

In streaming data applications incoming samples are processed and discar...

Please sign up or login with your details

Forgot password? Click here to reset