BadRes: Reveal the Backdoors through Residual Connection

09/15/2022
by   Mingrui He, et al.
0

Generally, residual connections are indispensable network components in building CNNs and Transformers for various downstream tasks in CV and VL, which encourages skip shortcuts between network blocks. However, the layer-by-layer loopback residual connections may also hurt the model's robustness by allowing unsuspecting input. In this paper, we proposed a simple yet strong backdoor attack method - BadRes, where the residual connections play as a turnstile to be deterministic on clean inputs while unpredictable on poisoned ones. We have performed empirical evaluations on four datasets with ViT and BEiT models, and the BadRes achieves 97 degradation on clean data. Moreover, we analyze BadRes with state-of-the-art defense methods and reveal the fundamental weakness lying in residual connections.

READ FULL TEXT

page 2

page 9

research
01/09/2017

Visualizing Residual Networks

Residual networks are the current state of the art on ImageNet. Similar ...
research
02/02/2021

Hardware-efficient Residual Networks for FPGAs

Residual networks (ResNets) employ skip connections in their networks – ...
research
08/09/2016

Residual Networks of Residual Networks: Multilevel Residual Networks

A residual-networks family with hundreds or even thousands of layers dom...
research
12/06/2016

Video Ladder Networks

We present the Video Ladder Network (VLN) for efficiently generating fut...
research
05/27/2019

Identity Connections in Residual Nets Improve Noise Stability

Residual Neural Networks (ResNets) achieve state-of-the-art performance ...
research
01/08/2021

Residual networks classify inputs based on their neural transient dynamics

In this study, we analyze the input-output behavior of residual networks...
research
11/27/2022

A Kernel Perspective of Skip Connections in Convolutional Networks

Over-parameterized residual networks (ResNets) are amongst the most succ...

Please sign up or login with your details

Forgot password? Click here to reset