paper-with-me

홈 › Papers

Check Your Other Door! Creating Backdoor Attacks in the Frequency Domain

2021-09-12 · Hasan Abed Al Kader Hammoud, Bernard Ghanem

Deep Neural Networks (DNNs) are ubiquitous and span a variety of applications ranging from image classification to real-time object detection. As DNN models become more sophisticated, the computational cost of training these models becomes a burden. For this reason, outsourcing the training process has been the go-to option for many DNN users. Unfortunately, this comes at the cost of vulnerability to backdoor attacks. These attacks aim to establish hidden backdoors in the DNN so that it performs well on clean samples, but outputs a particular target label when a trigger is applied to the input. Existing backdoor attacks either generate triggers in the spatial domain or naively poison frequencies in the Fourier domain. In this work, we propose a pipeline based on Fourier heatmaps to generate a spatially dynamic and invisible backdoor attack in the frequency domain. The proposed attack is extensively evaluated on various datasets and network architectures. Unlike most existing backdoor attacks, the proposed attack can achieve high attack success rates with low poisoning rates and little to no drop in performance while remaining imperceptible to the human eye. Moreover, we show that the models poisoned by our attack are resistant to various state-of-the-art (SOTA) defenses, so we contribute two possible defenses that can evade the attack.

📄 PDF Abstract BibTeX arXiv:2109.05507

Code (0)

등록된 구현이 없습니다.

Tasks

Backdoor Attackimage-classificationImage Classificationobject-detectionObject DetectionReal-Time Object Detection

Similar Papers 제목 키워드 기반

Your Agent Can Defend Itself against Backdoor Attacks

2025-06-10 · Li Changjiang, Liang Jiacheng, Cao Bochuan, Chen Jinghui 외

Despite their growing adoption across domains, large language model (LLM)-powered agents face significant security risks from backdoor attacks during training and fine-tuning. These compromised agents can subsequently be…

Large Language Model

Your LLM Agent Can Leak Your Data: Data Exfiltration via Backdoored Tool Use

2026-04-07 · Wuyang Zhang, Shichao Pei arxiv

Tool-use large language model (LLM) agents are increasingly deployed to support sensitive workflows, relying on tool calls for retrieval, external API access, and session memory management. While prior research has exami…

Beyond Native Success: Auditing Deployment-Interface Exposure of CLIP Backdoors

2026-06-16 · Kunlan Xiang, Haomiao Yang, Wenbo Jiang arxiv

Contrastive Language-Image Pre-training models are widely reused across downstream interfaces, including feature extraction, retrieval, reranking, and selection. Existing CLIP backdoor, however, usually validate attacks …

Pick Your Poison: Learning to Select Poison Sets for Stronger LLM Backdoor Attacks

2026-09-14 · Aashiq Muhamed, Mona T. Diab, Virginia Smith, Andrew Ilyas 외 hf

Backdoor poisoning attacks add poisoned examples to otherwise-clean finetuning data, pairing a trigger with a target behavior that the model learns to produce when the trigger appears. Existing evaluations typically fix …

Mind Your Heart: Stealthy Backdoor Attack on Dynamic Deep Neural Network in Edge Computing

2022-12-22 · Tian Dong, Ziyuan Zhang, Han Qiu, Tianwei Zhang 외

Transforming off-the-shelf deep neural network (DNN) models into dynamic multi-exit architectures can achieve inference and transmission efficiency by fragmenting and distributing a large DNN model in edge computing scen…

Backdoor AttackEdge-computing