paper-with-me

홈 › Papers

Few-shot Backdoor Attacks via Neural Tangent Kernels

2022-10-12 · Jonathan Hayase, Sewoong Oh

In a backdoor attack, an attacker injects corrupted examples into the training set. The goal of the attacker is to cause the final trained model to predict the attacker's desired target label when a predefined trigger is added to test inputs. Central to these attacks is the trade-off between the success rate of the attack and the number of corrupted training examples injected. We pose this attack as a novel bilevel optimization problem: construct strong poison examples that maximize the attack success rate of the trained model. We use neural tangent kernels to approximate the training dynamics of the model being attacked and automatically learn strong poison examples. We experiment on subclasses of CIFAR-10 and ImageNet with WideResNet-34 and ConvNeXt architectures on periodic and patch trigger attacks and show that NTBA-designed poisoned examples achieve, for example, an attack success rate of 90% with ten times smaller number of poison examples injected compared to the baseline. We provided an interpretation of the NTBA-designed attacks using the analysis of kernel linear regression. We further demonstrate a vulnerability in overparametrized deep neural networks, which is revealed by the shape of the neural tangent kernel.

📄 PDF Abstract BibTeX arXiv:2210.05929

Code (1)

SewoongLab/ntk-backdoor 공식 구현 jax

Tasks

Backdoor AttackBilevel Optimization

Methods 이 논문이 사용한 방법론

ConvNeXt 설명 없음
Test 설명 없음

Similar Papers 제목 키워드 기반

Does Few-shot Learning Suffer from Backdoor Attacks?

2023-12-31 · Xinwei Liu, Xiaojun Jia, Jindong Gu, Yuan Xun 외

The field of few-shot learning (FSL) has shown promising results in scenarios where training data is limited, but its vulnerability to backdoor attacks remains largely unexplored. We first explore this topic by first eva…

Backdoor AttackFew-Shot Learning

A Survey of Recent Backdoor Attacks and Defenses in Large Language Models

2024-06-10 · Shuai Zhao, Meihuizi Jia, Zhongliang Guo, Leilei Gan 외

Large Language Models (LLMs), which bridge the gap between human language understanding and complex problem-solving, achieve state-of-the-art performance on several NLP tasks, particularly in few-shot and zero-shot setti…

parameter-efficient fine-tuning

STONE: Pioneering the One-to-N Universal Backdoor Threat in 3D Point Cloud

2025-11-14 · Dongmei Shan, Wei Lian, Chongxia Wang arxiv

Backdoor attacks pose a critical threat to deep learning, especially in safety-sensitive 3D domains such as autonomous driving and robotics. While potent, existing attacks on 3D point clouds are predominantly limited to …

Autonomous DrivingPoint Clouds

Prompt as Triggers for Backdoor Attack: Examining the Vulnerability in Language Models

2023-05-02 · Shuai Zhao, Jinming Wen, Luu Anh Tuan, Junbo Zhao 외

The prompt-based learning paradigm, which bridges the gap between pre-training and fine-tuning, achieves state-of-the-art performance on several NLP tasks, particularly in few-shot settings. Despite being widely applied,…

Backdoor AttackFew-Shot Text Classificationtext-classificationText Classification

CLIBE: Detecting Dynamic Backdoors in Transformer-based NLP Models

2024-09-02 · Rui Zeng, Xi Chen, Yuwen Pu, Xuhong Zhang 외

Backdoors can be injected into NLP models to induce misbehavior when the input text contains a specific feature, known as a trigger, which the attacker secretly selects. Unlike fixed words, phrases, or sentences used in …

Text ClassificationText Generation