<p>In recent years, machine learning’s rapid growth has sparked security concerns, notably around backdoor attacks (<i>a.k.a., Trojan attacks</i>). However, while previous research has examined these attacks across domains like neural networks, there’s been little focus on backdoors in ensemble learning, despite their heightened risk. This paper presents DOBEL, the first method specialized to detect backdoor attacks in ensemble learning, especially those enabled by embedded triggers in training data. DOBEL employs carefully crafted test ensembles and analyzes feature vector magnitudes to distinguish benign models from malicious ones. Crucially, it addresses limitations of existing defenses which rely on sensitive training data. Experimental results show DOBEL’s effectiveness, with 98.9% accuracy in identifying Trojaned ensembles and rapid decision-making for a 50-model ensemble in 0.024 milliseconds.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

DOBEL: detecting backdoors in ensemble learning

  • SeokHee Kim,
  • Changhee Hahn

摘要

In recent years, machine learning’s rapid growth has sparked security concerns, notably around backdoor attacks (a.k.a., Trojan attacks). However, while previous research has examined these attacks across domains like neural networks, there’s been little focus on backdoors in ensemble learning, despite their heightened risk. This paper presents DOBEL, the first method specialized to detect backdoor attacks in ensemble learning, especially those enabled by embedded triggers in training data. DOBEL employs carefully crafted test ensembles and analyzes feature vector magnitudes to distinguish benign models from malicious ones. Crucially, it addresses limitations of existing defenses which rely on sensitive training data. Experimental results show DOBEL’s effectiveness, with 98.9% accuracy in identifying Trojaned ensembles and rapid decision-making for a 50-model ensemble in 0.024 milliseconds.