Compression-Resistant Backdoor Attack against Deep Neural Networks

01/03/2022
by   Mingfu Xue, et al.
0

In recent years, many backdoor attacks based on training data poisoning have been proposed. However, in practice, those backdoor attacks are vulnerable to image compressions. When backdoor instances are compressed, the feature of specific backdoor trigger will be destroyed, which could result in the backdoor attack performance deteriorating. In this paper, we propose a compression-resistant backdoor attack based on feature consistency training. To the best of our knowledge, this is the first backdoor attack that is robust to image compressions. First, both backdoor images and their compressed versions are input into the deep neural network (DNN) for training. Then, the feature of each image is extracted by internal layers of the DNN. Next, the feature difference between backdoor images and their compressed versions are minimized. As a result, the DNN treats the feature of compressed images as the feature of backdoor images in feature space. After training, the backdoor attack against DNN is robust to image compression. Furthermore, we consider three different image compressions (i.e., JPEG, JPEG2000, WEBP) in feature consistency training, so that the backdoor attack is robust to multiple image compression algorithms. Experimental results demonstrate the effectiveness and robustness of the proposed backdoor attack. When the backdoor instances are compressed, the attack success rate of common backdoor attack is lower than 10 attack success rate of our compression-resistant backdoor is greater than 97 The compression-resistant attack is still robust even when the backdoor images are compressed with low compression quality. In addition, extensive experiments have demonstrated that, our compression-resistant backdoor attack has the generalization ability to resist image compression which is not used in the training process.

READ FULL TEXT

page 1

page 3

page 6

research
01/31/2022

Imperceptible and Multi-channel Backdoor Attack against Deep Neural Networks

Recent researches demonstrate that Deep Neural Networks (DNN) models are...
research
03/16/2018

Towards Image Understanding from Deep Compression without Decoding

Motivated by recent work on deep neural network (DNN)-based image compre...
research
02/28/2023

Backdoor Attacks Against Deep Image Compression via Adaptive Frequency Trigger

Recent deep-learning-based compression methods have achieved superior pe...
research
02/19/2018

Shield: Fast, Practical Defense and Vaccination for Deep Learning using JPEG Compression

The rapidly growing body of research in adversarial machine learning has...
research
12/06/2021

Fast Test Input Generation for Finding Deviated Behaviors in Compressed Deep Neural Network

Model compression can significantly reduce sizes of deep neural network ...
research
11/25/2022

Training Data Improvement for Image Forgery Detection using Comprint

Manipulated images are a threat to consumers worldwide, when they are us...
research
02/17/2020

Discernible Compressed Images via Deep Perception Consistency

Image compression, as one of the fundamental low-level image processing ...

Please sign up or login with your details

Forgot password? Click here to reset