Programmable Neural Network Trojan for Pre-Trained Feature Extractor

01/23/2019
by   Yu Ji, et al.
0

Neural network (NN) trojaning attack is an emerging and important attack model that can broadly damage the system deployed with NN models. Existing studies have explored the outsourced training attack scenario and transfer learning attack scenario in some small datasets for specific domains, with limited numbers of fixed target classes. In this paper, we propose a more powerful trojaning attack method for both outsourced training attack and transfer learning attack, which outperforms existing studies in the capability, generality, and stealthiness. First, The attack is programmable that the malicious misclassification target is not fixed and can be generated on demand even after the victim's deployment. Second, our trojan attack is not limited in a small domain; one trojaned model on a large-scale dataset can affect applications of different domains that reuse its general features. Thirdly, our trojan design is hard to be detected or eliminated even if the victims fine-tune the whole model.

READ FULL TEXT

page 3

page 5

research
04/20/2020

Headless Horseman: Adversarial Attacks on Transfer Learning Models

Transfer learning facilitates the training of task-specific classifiers ...
research
04/08/2019

A Target-Agnostic Attack on Deep Models: Exploiting Security Vulnerabilities of Transfer Learning

Due to the lack of enough training data and high computational cost to t...
research
02/27/2019

FixyNN: Efficient Hardware for Mobile Computer Vision via Transfer Learning

The computational demands of computer vision tasks based on state-of-the...
research
12/04/2018

Energy Efficient Hardware for On-Device CNN Inference via Transfer Learning

On-device CNN inference for real-time computer vision applications can r...
research
09/07/2023

Learning from Limited Heterogeneous Training Data: Meta-Learning for Unsupervised Zero-Day Web Attack Detection across Web Domains

Recently unsupervised machine learning based systems have been developed...
research
01/18/2023

Targeted Image Reconstruction by Sampling Pre-trained Diffusion Model

A trained neural network model contains information on the training data...
research
03/03/2022

On partitioning of an SHM problem and parallels with transfer learning

In the current work, a problem-splitting approach and a scheme motivated...

Please sign up or login with your details

Forgot password? Click here to reset