paper-with-me

홈 › Papers

Defense Against Multi-target Trojan Attacks

2022-07-08 · Haripriya Harikumar, Santu Rana, Kien Do, Sunil Gupta, Wei Zong, Willy Susilo, Svetha Venkastesh

Adversarial attacks on deep learning-based models pose a significant threat to the current AI infrastructure. Among them, Trojan attacks are the hardest to defend against. In this paper, we first introduce a variation of the Badnet kind of attacks that introduces Trojan backdoors to multiple target classes and allows triggers to be placed anywhere in the image. The former makes it more potent and the latter makes it extremely easy to carry out the attack in the physical space. The state-of-the-art Trojan detection methods fail with this threat model. To defend against this attack, we first introduce a trigger reverse-engineering mechanism that uses multiple images to recover a variety of potential triggers. We then propose a detection mechanism by measuring the transferability of such recovered triggers. A Trojan trigger will have very high transferability i.e. they make other images also go to the same class. We study many practical advantages of our attack method and then demonstrate the detection performance using a variety of image datasets. The experimental results show the superior detection performance of our method over the state-of-the-arts.

📄 PDF Abstract BibTeX arXiv:2207.03895

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Trojan Horse Training for Breaking Defenses against Backdoor Attacks in Deep Learning

2022-03-25 · Arezoo Rajabi, Bhaskar Ramasubramanian, Radha Poovendran

Machine learning (ML) models that use deep neural networks are vulnerable to backdoor attacks. Such attacks involve the insertion of a (hidden) trigger by an adversary. As a consequence, any input that contains the trigg…

Backdoor Attack

Towards Effective and Robust Neural Trojan Defenses via Input Filtering

2022-02-24 · Kien Do, Haripriya Harikumar, Hung Le, Dung Nguyen 외

Trojan attacks on deep neural networks are both dangerous and surreptitious. Over the past few years, Trojan attacks have advanced from using only a single input-agnostic trigger and targeting only one class to using mul…

Data Compressioninput filteringVariational Inference

T-Miner: A Generative Approach to Defend Against Trojan Attacks on DNN-based Text Classification

2021-03-07 · Ahmadreza Azizi, Ibrahim Asadullah Tahmid, Asim Waheed, Neal Mangaokar 외

Deep Neural Network (DNN) classifiers are known to be vulnerable to Trojan or backdoor attacks, where the classifier is manipulated such that it misclassifies any input containing an attacker-determined Trojan trigger. B…

text-classificationText Classification

TrojFlow: Flow Models are Natural Targets for Trojan Attacks

2024-12-21 · Zhengyang Qi, Xiaohua Xu

Flow-based generative models (FMs) have rapidly advanced as a method for mapping noise to data, its efficient training and sampling process makes it widely applicable in various fields. FMs can be viewed as a variant of …

Specificity

Rethinking IC layout vulnerability: Simulation-based hardware Trojan threat assessment with high fidelity

2024-05-19 · IEEE Symposium on Security and Privacy (SP) 2024 5 · Xinming Wei, Jiaxi Zhang, Guojie Luo

Due to the escalating complexity of chip design and the exorbitant cost of building cutting-edge manufacturing facilities, outsourcing the fabrication of Integrated Circuits (ICs) is prevalent in modern semiconductor ind…

Side Channel Analysis