Design and Evaluation of a Multi-Domain Trojan Detection Method on Deep Neural Networks

11/23/2019
by   Yansong Gao, et al.
0

This work corroborates a run-time Trojan detection method exploiting STRong Intentional Perturbation of inputs, is a multi-domain Trojan detection defence across Vision, Text and Audio domains—thus termed as STRIP-ViTA. Specifically, STRIP-ViTA is the first confirmed Trojan detection method that is demonstratively independent of both the task domain and model architectures. We have extensively evaluated the performance of STRIP-ViTA over: i) CIFAR10 and GTSRB datasets using 2D CNNs, and a public third party Trojaned model for vision tasks; ii) IMDB and consumer complaint datasets using both LSTM and 1D CNNs for text tasks; and speech command dataset using both 1D CNNs and 2D CNNs for audio tasks. Experimental results based on 28 tested Trojaned models demonstrate that STRIP-ViTA performs well across all nine architectures and five datasets. In general, STRIP-ViTA can effectively detect Trojan inputs with small false acceptance rate (FAR) with an acceptable preset false rejection rate (FRR). In particular, for vision tasks, we can always achieve a 0 FAR. By setting FRR to be 3 text and audio tasks, respectively. Moreover, we have evaluated and shown the effectiveness of STRIP-ViTA against a number of advanced backdoor attacks whilst other state-of-the-art methods lose effectiveness in front of one or all of these advanced backdoor attacks.

READ FULL TEXT
research
02/18/2019

STRIP: A Defence Against Trojan Attacks on Deep Neural Networks

Recent trojan attacks on deep neural network (DNN) models are one insidi...
research
10/27/2022

On Out-of-Distribution Detection for Audio with Deep Nearest Neighbors

Out-of-distribution (OOD) detection is concerned with identifying data p...
research
11/18/2022

Intrusion Detection in Internet of Things using Convolutional Neural Networks

Internet of Things (IoT) has become a popular paradigm to fulfil needs o...
research
12/19/2018

Rotation Ensemble Module for Detecting Rotation-Invariant Features

Deep learning has improved many computer vision tasks by utilizing data-...
research
10/08/2020

Decamouflage: A Framework to Detect Image-Scaling Attacks on Convolutional Neural Networks

As an essential processing step in computer vision applications, image r...
research
05/14/2018

Learning Dual Convolutional Neural Networks for Low-Level Vision

In this paper, we propose a general dual convolutional neural network (D...
research
08/07/2022

PDO-s3DCNNs: Partial Differential Operator Based Steerable 3D CNNs

Steerable models can provide very general and flexible equivariance by f...

Please sign up or login with your details

Forgot password? Click here to reset