Summary and Future Directions
摘要
This monograph aims at the issue of backdoor attacks in artificial intelligence, with the invisibility of backdoor triggers designed from the perspective of human vision as the research target. A new type of invisible backdoor attack was designed for DNN models in the field of image classification and natural language processing. Lastly, for backdoor attacks in the federated learning system, an analysis was introduced from the perspective of cooperative games, and a detection framework based on Shapley values was presented. The main contents of this monograph are as follows.