Advanced Search

    LIU Jishun, GENG Peilin, HONG Wei, ZHANG Xueqin. Dynamic Invisible Backdoor Sample Generation based on Spatial-Spectral DomainJ. Journal of East China University of Science and Technology. DOI: 10.14135/j.cnki.1006-3080.20260212002
    Citation: LIU Jishun, GENG Peilin, HONG Wei, ZHANG Xueqin. Dynamic Invisible Backdoor Sample Generation based on Spatial-Spectral DomainJ. Journal of East China University of Science and Technology. DOI: 10.14135/j.cnki.1006-3080.20260212002

    Dynamic Invisible Backdoor Sample Generation based on Spatial-Spectral Domain

    • The rapid development of deep learning technologies has allowed deep neural networks to achieve remarkable performance across a wide range of fields. Nevertheless, the growing prevalence of backdoor attacks exposes critical vulnerabilities in deep neural networks under such adversarial settings. To tackle the problem that triggers embedded in existing backdoor samples can be easily detected during test phases, this work improves the stealthiness of poisoned samples from both the spatial and frequency domains and proposes a dynamic invisible backdoor generation framework named S2D-DIBA (Spatial-Spectral Domain Dynamic Invisible Backdoor Attack). In the spatial branch, we design a generator built upon Attention U-Net. Leveraging the attention mechanism, the generator concentrates on salient image regions to produce a probabilistic modification matrix. A multilayer perceptron dubbed SampleNet is introduced to simulate a differentiable sampling strategy, enabling pixel-wise optimization over critical areas. This yields unique, covert spatial triggers customized for each clean image. In the frequency branch, both clean images and samples embedded with spatial triggers are converted to the frequency domain via discrete cosine transform (DCT). We construct a frequency-domain similarity loss to narrow the distribution gap of high-frequency components between poisoned and benign samples, which further boosts the visual stealth of backdoor instances. Extensive experiments on two public datasets validate that our proposed framework surpasses existing state-of-the-art baselines. Compared with the second-best method, our approach reduces the L1 norm perturbation by over 50× while retaining an attack success rate higher than 99.9%, which achieves a favorable trade-off between attack effectiveness and trigger concealment.
    • loading

    Catalog

      /

      DownLoad:  Full-Size Img  PowerPoint
      Return
      Return