Pith. sign in

REVIEW 2 cited by

Check Your Other Door! Creating Backdoor Attacks in the Frequency Domain

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2109.05507 v3 pith:BSY4UKLA submitted 2021-09-12 cs.CR cs.CVcs.LG

classification cs.CRcs.CVcs.LG
keywords attackattacksbackdoordomainmodelscostdefensesexisting
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Deep Neural Networks (DNNs) are ubiquitous and span a variety of applications ranging from image classification to real-time object detection. As DNN models become more sophisticated, the computational cost of training these models becomes a burden. For this reason, outsourcing the training process has been the go-to option for many DNN users. Unfortunately, this comes at the cost of vulnerability to backdoor attacks. These attacks aim to establish hidden backdoors in the DNN so that it performs well on clean samples, but outputs a particular target label when a trigger is applied to the input. Existing backdoor attacks either generate triggers in the spatial domain or naively poison frequencies in the Fourier domain. In this work, we propose a pipeline based on Fourier heatmaps to generate a spatially dynamic and invisible backdoor attack in the frequency domain. The proposed attack is extensively evaluated on various datasets and network architectures. Unlike most existing backdoor attacks, the proposed attack can achieve high attack success rates with low poisoning rates and little to no drop in performance while remaining imperceptible to the human eye. Moreover, we show that the models poisoned by our attack are resistant to various state-of-the-art (SOTA) defenses, so we contribute two possible defenses that can evade the attack.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. LADDER: Multi-objective Backdoor Attack via Evolutionary Algorithm

    cs.CR 2024-11 conditional novelty 7.0 of 10

    LADDER uses multi-objective evolutionary optimization to craft low-frequency backdoor triggers that are simultaneously effective, invisible in spatial and spectral domains, and robust against common image preprocessing.

  2. Stealthy and Robust Backdoor Attack against 3D Point Clouds through Additional Point Features

    cs.CV 2024-12 conditional novelty 6.0 of 10

    A backdoor trigger made by uniformly shifting additional point features (normals or intensity) achieves over 94% attack success on 3D point cloud classifiers while surviving geometric preprocessing.

Pith tools