Regula Sub-rosa: Latent Backdoor Attacks on Deep Neural Networks

05/24/2019
by   Yuanshun Yao, et al.
0

Recent work has proposed the concept of backdoor attacks on deep neural networks (DNNs), where misbehaviors are hidden inside "normal" models, only to be triggered by very specific inputs. In practice, however, these attacks are difficult to perform and highly constrained by sharing of models through transfer learning. Adversaries have a small window during which they must compromise the student model before it is deployed. In this paper, we describe a significantly more powerful variant of the backdoor attack, latent backdoors, where hidden rules can be embedded in a single "Teacher" model, and automatically inherited by all "Student" models through the transfer learning process. We show that latent backdoors can be quite effective in a variety of application contexts, and validate its practicality through real-world attacks against traffic sign recognition, iris identification of lab volunteers, and facial recognition of public figures (politicians). Finally, we evaluate 4 potential defenses, and find that only one is effective in disrupting latent backdoors, but might incur a cost in classification accuracy as tradeoff.

READ FULL TEXT

page 3

page 4

page 7

page 8

page 9

page 11

page 12

page 13

research
08/29/2019

Defending Against Misclassification Attacks in Transfer Learning

Transfer learning accelerates the development of new models (Student Mod...
research
06/25/2020

Backdoor Attacks on Facial Recognition in the Physical World

Backdoor attacks embed hidden malicious behaviors inside deep neural net...
research
07/17/2023

Adversarial Attacks on Traffic Sign Recognition: A Survey

Traffic sign recognition is an essential component of perception in auto...
research
11/12/2015

Representational Distance Learning for Deep Neural Networks

Deep neural networks (DNNs) provide useful models of visual representati...
research
06/20/2020

FaceHack: Triggering backdoored facial recognition systems using facial characteristics

Recent advances in Machine Learning (ML) have opened up new avenues for ...
research
03/15/2022

A Wearables-Driven Attack on Examination Proctoring

Multiple choice questions are at the heart of many standardized tests an...
research
01/10/2020

Backdoor Attacks against Transfer Learning with Pre-trained Deep Learning Models

Transfer learning, that transfer the learned knowledge of pre-trained Te...

Please sign up or login with your details

Forgot password? Click here to reset