paper-with-me

Papers

Everyone Can Attack: Repurpose Lossy Compression as a Natural Backdoor Attack

2023-08-31 · Sze Jue Yang, Quang Nguyen, Chee Seng Chan, Khoa D. Doan

The vulnerabilities to backdoor attacks have recently threatened the trustworthiness of machine learning models in practical applications. Conventional wisdom suggests that not everyone can be an attacker since the process of designing the trigger generation algorithm often involves significant effort and extensive experimentation to ensure the attack's stealthiness and effectiveness. Alternatively, this paper shows that there exists a more severe backdoor threat: anyone can exploit an easily-accessible algorithm for silent backdoor attacks. Specifically, this attacker can employ the widely-used lossy image compression from a plethora of compression tools to effortlessly inject a trigger pattern into an image without leaving any noticeable trace; i.e., the generated triggers are natural artifacts. One does not require extensive knowledge to click on the "convert" or "save as" button while using tools for lossy image compression. Via this attack, the adversary does not need to design a trigger generator as seen in prior works and only requires poisoning the data. Empirically, the proposed attack consistently achieves 100% attack success rate in several benchmark datasets such as MNIST, CIFAR-10, GTSRB and CelebA. More significantly, the proposed attack can still achieve almost 100% attack success rate with very small (approximately 10%) poisoning rates in the clean label setting. The generated trigger of the proposed attack using one lossy compression algorithm is also transferable across other related compression algorithms, exacerbating the severity of this backdoor threat. This work takes another crucial step toward understanding the extensive risks of backdoor attacks in practice, urging practitioners to investigate similar attacks and relevant backdoor mitigation methods.

📄 PDF Abstract BibTeX arXiv:2308.16684

Code (0)

등록된 구현이 없습니다.

Tasks

Backdoor AttackImage Compression

Similar Papers 제목 키워드 기반

Inevitable Encounters: Backdoor Attacks Involving Lossy Compression

2026-03-14 · Qian Li, Yunuo Chen, Yuntian Chen arxiv

Real-world backdoor attacks often require poisoned datasets to be stored and transmitted before being used to compromise deep learning systems. However, in the era of big data, the inevitable use of lossy compression pos…

Image Compression

Keep It Real: Challenges in Attacking Compression-Based Adversarial Purification

2025-08-07 · Samuel Räber, Till Aczel, Andreas Plesner, Roger Wattenhofer arxiv

Previous work has suggested that preprocessing images through lossy compression can defend against adversarial perturbations, but comprehensive attack evaluations have been lacking. In this paper, we construct strong whi…

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents

2025-10-27 · Zesen Liu, Zhixiang Zhang, Yuchong Xie, Dongdong She arxiv

Prompt compression is increasingly deployed in LLM agents to reduce latency and cost, but it also determines what the backend LLM ultimately sees. We show that, when trusted and untrusted inputs are compressed under a sh…

The Effect of Lossy Compression on 3D Medical Images Segmentation with Deep Learning

2024-09-25 · Anvar Kurmukov, Bogdan Zavolovich, Aleksandra Dalechina, Vladislav Proskurov 외

Image compression is a critical tool in decreasing the cost of storage and improving the speed of transmission over the internet. While deep learning applications for natural images widely adopts the usage of lossy compr…

Image Compression

Towards Robust Data Hiding Against (JPEG) Compression: A Pseudo-Differentiable Deep Learning Approach

2020-12-30 · Chaoning Zhang, Adil Karjauv, Philipp Benz, In So Kweon

Data hiding is one widely used approach for protecting authentication and ownership. Most multimedia content like images and videos are transmitted or saved in the compressed form. This kind of lossy compression, such as…