错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Feature Transfer-Based Stealthy Poisoning Attack for DNNs

  • Jinyin Chen,
  • Ximin Zhang,
  • Haibin Zheng

摘要

Intentionally polluting training data with specific triggers can lead to poisoning attacks on deep neural networks. Defense algorithms can easily detect these poisoning samples, as existing episodes mainly focused on attack success rate with patch-based samples. In order to address this problem, we propose a novel adversarial network of one generator and two discriminators called our method. The generator extracts the hidden features of the target class automatically and incorporates them into benign training samples. The ratio of the poisoning perturbation is controlled by one discriminator. The other discriminator works as the target model to testify the poisoning effects. Our method’s unique feature is that its poisoned training samples are indistinguishable from benign ones by both defensive methods and manual visual inspection, and even benign test samples can be utilized to carry out the attack. It is shown by extensive experiments that our method can achieve a state-of-the-art attack success rate, as high as 91.74%, with only 7% poisoned samples on publicly available datasets LFW and CASIA. Furthermore, we have experimented with high-performance defense algorithms such as autodecoder defense and DBSCAN cluster detection and showed the resilience of our method.