1.Key Laboratory of Aerospace Information Security and Trusted Computing,Ministry of Education,School of Cyber Science and Engineering,Wuhan University,Wuhan 430072,Hubei,China
2.Rizhao Institute of Information Technology,Wuhan University,Rizhao 276800,Shandong,China
3.Collaborative Innovation Center of Geospatial Technology,Wuhan 430079,Hubei,China
Most existing research on backdoor attacks has primarily focused on simple backdoor mapping strategies, such as all-to-one mapping. This approach overlooks the need for more complex mapping strategies in real-world attack scenarios, thereby limiting the flexibility and effectiveness of backdoor attacks. To solve the problem, this article proposes a backdoor attack framework with an adjustable mapping strategy, and implements a backdoor attack based on complex mapping, called CMBA. By introducing evasion classes and the multi-target setting, CMBA can precisely control the attack scope, and establish complex correspondences between different original classes and multiple target classes, thereby improving the flexibility of attacks. The experimental results show that CMBA performs well on three datasets. In addition, by introducing more evasion classes and target classes, CMBA becomes stealthier and successfully bypasses the detection of several current mainstream backdoor defenses.
KRIZHEVSKYA, SUTSKEVERI, HINTONG E. ImageNet classification with deep convolutional neural networks[J]. Communications of the ACM, 2017, 60(6): 84-90. DOI: 10.1145/3065386 .
[2]
HEK M, ZHANGX Y, RENS Q, et al. Deep residual learning for image recognition[C]//2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). New York: IEEE Press, 2016: 770-778. DOI: 10.1109/CVPR.2016.90 .
[3]
GRAVESA, MOHAMEDA R, HINTONG. Speech recognition with deep recurrent neural networks[C]//2013 IEEE International Conference on Acoustics, Speech and Signal Processing. New York: IEEE Press, 2013: 6645-6649. DOI: 10.1109/ICASSP.2013.6638947 .
[4]
ZHAOS H, MAX J, ZHENGX, et al. Clean-label backdoor attacks on video recognition models[C]//2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). New York: IEEE Press, 2020: 14431-14440. DOI: 10.1109/CVPR42600.2020.01445 .
[5]
LIUY F, MAX J, BAILEYJ, et al. Reflection backdoor: A natural backdoor attack on deep neural networks[C]//European Conference on Computer Vision. Cham: Springer, 2020: 182-199.10.1007/978-3-030-58607-2_11. DOI: 10.1007/978-3-030-58607-2_11 .
[6]
CHENGS Y, LIUY Q, MAS Q, et al. Deep feature space Trojan attack of neural networks by controlled detoxification[J]. Proceedings of the AAAI Conference on Artificial Intelligence, 2021, 35(2): 1148-1156. DOI: 10.1609/aaai.v35i2.16201 .
[7]
LIY Z, LIY M, WUB Y, et al. Invisible backdoor attack with sample-specific triggers[C]//2021 IEEE/CVF International Conference on Computer Vision (ICCV). New York: IEEE Press, 2022: 16443-16452. DOI: 10.1109/ICCV48922.2021.01615 .
[8]
GUT Y, LIUK, DOLAN-GAVITTB, et al. BadNets: Evaluating backdooring attacks on deep neural networks[J]. IEEE Access, 2019, 7: 47230-47244. DOI: 10.1109/ACCESS.2019.2909068 .
[9]
TRUONGL, JONESC, HUTCHINSONB, et al. Systematic evaluation of backdoor data poisoning attacks on image classifiers[C]//2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW). New York: IEEE Press, 2020: 3422-3431. DOI: 10.1109/CVPRW50498.2020.00402 .
[10]
XIANGZ, MILLERD J, KESIDISG. A benchmark study of backdoor data poisoning defenses for deep neural network classifiers and a novel defense[C]//2019 IEEE 29th International Workshop on Machine Learning for Signal Processing (MLSP). New York: IEEE Press, 2019: 1-6. DOI: 10.1109/MLSP.2019.8918908 .
[11]
LIS F, XUEM H, ZHAOB Z H, et al. Invisible backdoor attacks on deep neural networks via steganography and regularization[J]. IEEE Transactions on Dependable and Secure Computing, 2021, 18(5): 2088-2105. DOI: 10.1109/TDSC.2020.3021407 .
[12]
RAKINA S, HEZ Z, FAND L. TBT: Targeted neural network attack with bit Trojan[C]//2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). New York: IEEE Press, 2020: 13195-13204. DOI: 10.1109/CVPR42600.2020.01321 .
[13]
LIY C, HUAJ Y, WANGH Y, et al. DeepPayload: Black-box backdoor attack on deep learning models through neural payload injection[C]//2021 IEEE/ACM 43rd International Conference on Software Engineering (ICSE). New York: IEEE Press, 2021: 263-274. DOI: 10.1109/ICSE43902.2021.00035 .
[14]
ZHANGQ, DINGY F, TIANY Q, et al. AdvDoor: Adversarial backdoor attack of deep learning system[C]//Proceedings of the 30th ACM SIGSOFT International Symposium on Software Testing and Analysis. New York: ACM, 2021: 127-138. DOI: 10.1145/3460319.3464809 .
[15]
NGUYENT A, TRANA. Input-aware dynamic backdoor attack[J]. Advances in Neural Information Processing Systems, 2020, 33: 3454-3464.
[16]
KOLOURIS, SAHAA, PIRSIAVASHH, et al. Universal litmus patterns: Revealing backdoor attacks in CNNs[C]//2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). New York: IEEE Press, 2020: 298-307. DOI: 10.1109/CVPR42600.2020.00038 .
[17]
LECUNY, BOSERB, DENKERJ S, et al. Backpropagation applied to handwritten zip code recognition[J]. Neural Computation, 1989, 1(4): 541-551. DOI: 10.1162/neco.1989.1.4.541 .
STALLKAMPJ, SCHLIPSINGM, SALMENJ, et al. The German traffic sign recognition benchmark: A multi-class classification competition[C]//The 2011 International Joint Conference on Neural Networks. New York: IEEE Press, 2011: 1453-1460. DOI: 10.1109/IJCNN.2011.6033395 .
[20]
HEK M, ZHANGX Y, RENS Q, et al. Identity mappings in deep residual networks[C]//European Conference on Computer Vision. Cham: Springer, 2016: 630-645.10.1007/978-3-319-46493-0_38. DOI: 10.1007/978-3-319-46493-0_38 .
[21]
YAOY S, LIH Y, ZHENGH T, et al. Latent backdoor attacks on deep neural networks[C]//Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM, 2019: 2041-2055. DOI: 10.1145/3319535.3354209 .
[22]
LIUY Q, MAS Q, AAFERY, et al. Trojaning attack on neural networks[C]//Proceedings 2018 Network and Distributed System Security Symposium. 2018: 1-15. DOI: 10.14722/ndss.2018.23291 .
LIUK, DOLAN-GAVITTB, GARGS. Fine-pruning: Defending against backdooring attacks on deep neural networks[C]//International Symposium on Research in Attacks, Intrusions, and Defenses. Cham: Springer, 2018: 273-294. DOI: 10.1007/978-3-030-00470-5_13 .
[25]
WANGB L, YAOY S, SHANS, et al. Neural cleanse: Identifying and mitigating backdoor attacks in neural networks[C]//2019 IEEE Symposium on Security and Privacy (SP). New York: IEEE Press, 2019: 707-723. DOI: 10.1109/SP.2019.00031 .
[26]
DOANB G, ABBASNEJADE, RANASINGHED C. Februus: Input purification defense against Trojan attacks on deep neural network systems[C]//ACSAC'20: Annual Computer Security Applications Conference. New York: ACM, 2020: 897-912. DOI: 10.1145/3427228.3427264 .
[27]
SELVARAJUR R, COGSWELLM, DAS A, et al. Grad-CAM: Visual explanations from deep networks via gradient-based localization[C]//2017 IEEE International Conference on Computer Vision (ICCV). New York: IEEE Press, 2017: 618-626. DOI: 10.1109/ICCV.2017.74 .