Backdooring Convolutional Neural Networks via Targeted Weight Perturbations

12/07/2018
by   Jacob Dumford, et al.
0

We present a new type of backdoor attack that exploits a vulnerability of convolutional neural networks (CNNs) that has been previously unstudied. In particular, we examine the application of facial recognition. Deep learning techniques are at the top of the game for facial recognition, which means they have now been implemented in many production-level systems. Alarmingly, unlike other commercial technologies such as operating systems and network devices, deep learning-based facial recognition algorithms are not presently designed with security requirements or audited for security vulnerabilities before deployment. Given how young the technology is and how abstract many of the internal workings of these algorithms are, neural network-based facial recognition systems are prime targets for security breaches. As more and more of our personal information begins to be guarded by facial recognition (e.g., the iPhone X), exploring the security vulnerabilities of these systems from a penetration testing standpoint is crucial. Along these lines, we describe a general methodology for backdooring CNNs via targeted weight perturbations. Using a five-layer CNN and ResNet-50 as case studies, we show that an attacker is able to significantly increase the chance that inputs they supply will be falsely accepted by a CNN while simultaneously preserving the error rates for legitimate enrolled classes.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/19/2021

Facial Expressions Recognition with Convolutional Neural Networks

Over the centuries, humans have developed and acquired a number of ways ...
research
10/10/2015

Do Deep Neural Networks Learn Facial Action Units When Doing Expression Recognition?

Despite being the appearance-based classifier of choice in recent years,...
research
05/22/2017

Facial Expression Recognition Using Enhanced Deep 3D Convolutional Neural Networks

Deep Neural Networks (DNNs) have shown to outperform traditional methods...
research
03/24/2019

Approximation and Non-parametric Estimation of ResNet-type Convolutional Neural Networks

Convolutional neural networks (CNNs) have been shown to achieve optimal ...
research
10/29/2019

Adversarial Example in Remote Sensing Image Recognition

With the wide application of remote sensing technology in various fields...
research
06/20/2020

FaceHack: Triggering backdoored facial recognition systems using facial characteristics

Recent advances in Machine Learning (ML) have opened up new avenues for ...
research
10/15/2020

AI-based BMI Inference from Facial Images: An Application to Weight Monitoring

Self-diagnostic image-based methods for healthy weight monitoring is gai...

Please sign up or login with your details

Forgot password? Click here to reset