高级检索

    基于空域和频域的动态不可见后门样本生成

    Dynamic Invisible Backdoor Sample Generation based on Spatial-Spectral Domain

    • 摘要: 深度学习技术的快速发展使其在多领域成效显著,但后门攻击的频发暴露了深度神经网络的脆弱性。针对后门样本触发器易暴露的问题,为了实现高质量的模拟攻击测试以提升模型安全性,本文提出动态不可见后门样本生成框架S2D-DIBA(Spatial-Spectral Domain Dynamic Invisible Backdoor Attack),从空域与频域协同提升样本隐蔽性。空域设计基于Attention U-Net的生成器,借注意力机制聚焦图像关键区域,结合SampleNet实现可微分采样,完成像素级优化以生成样本专属隐蔽触发器;频域通过离散余弦变换转换中毒图像,设计频域相似性损失缩小与干净样本高频分布差异。两组公共数据集实验表明,该算法性能优于现有方法,较次优方案L1范数降低50倍以上,攻击成功率维持99.9%以上,在有效性与隐蔽性上均表现优异。

       

      Abstract: The rapid development of deep learning technologies has allowed deep neural networks to achieve remarkable performance across a wide range of fields. Nevertheless, the growing prevalence of backdoor attacks exposes critical vulnerabilities in deep neural networks under such adversarial settings. To tackle the problem that triggers embedded in existing backdoor samples can be easily detected during test phases, this work improves the stealthiness of poisoned samples from both the spatial and frequency domains and proposes a dynamic invisible backdoor generation framework named S2D-DIBA (Spatial-Spectral Domain Dynamic Invisible Backdoor Attack). In the spatial branch, we design a generator built upon Attention U-Net. Leveraging the attention mechanism, the generator concentrates on salient image regions to produce a probabilistic modification matrix. A multilayer perceptron dubbed SampleNet is introduced to simulate a differentiable sampling strategy, enabling pixel-wise optimization over critical areas. This yields unique, covert spatial triggers customized for each clean image. In the frequency branch, both clean images and samples embedded with spatial triggers are converted to the frequency domain via discrete cosine transform (DCT). We construct a frequency-domain similarity loss to narrow the distribution gap of high-frequency components between poisoned and benign samples, which further boosts the visual stealth of backdoor instances. Extensive experiments on two public datasets validate that our proposed framework surpasses existing state-of-the-art baselines. Compared with the second-best method, our approach reduces the L1 norm perturbation by over 50× while retaining an attack success rate higher than 99.9%, which achieves a favorable trade-off between attack effectiveness and trigger concealment.

       

    /

    返回文章
    返回