An Invisible Backdoor Attack based on DCT-Injection

2022 IEEE International Conference on Unmanned Systems (ICUS)(2022)

引用 0|浏览7
暂无评分
摘要
In recent years, as deep learning models have been widely used, the research on the security of network models attracts more and more attention. As a novel type of attack method, backdoor attacks pose a great threat to the models due to their stealthiness. To improve the security of network models, possible backdoor attacks need to be investigated. The current mainstream backdoor attacks embed trigger patterns to images in the spatial domain, which makes their trigger patterns observable. To solve this problem, an invisible backdoor attack based on discrete cosine transform (DCT) injection is proposed in this paper, which injects backdoor information in the frequency domain by using DCT. Experiments on three different models with CIFAR-10 dataset demonstrate that the proposed method is more effective and stealthier than the spatial domain embedding backdoor attack. It is further demonstrated that the proposed method is resistant to Fine-Pruning defense by comparing it with mainstream backdoor attacks.
更多
查看译文
关键词
deep learning,backdoor attacks,DCT,injection,frequency
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要