Invisible backdoor learning in regional transform domain
摘要
The rapid developing deep learning is highly required by resources and computing resources, which easily leads to backdoor learnings. It is difficult for existing schemes to strike a balance among trigger concealment, the effect and the stability. Sometimes, simple manipulation of the image may disable the trigger. In this paper, we propose an invisible backdoor learning scheme in regional transform domain. The high-frequency region remains unchanged while the left region is transformed so that the trigger is added in the high frequency. Experimental results show that the attack success rate (ASR) of our scheme reaches more than 99%, while the accuracy of the model (BA) decreases by less than 1%. Our scheme can resist common defense methods and the samples; visual quality of our scheme is better than others.