Invisible Backdoor Attack Through Singular Value Decomposition
摘要
With the widespread integration of deep learning across diverse fields, attention to its security is mounting. Among the array of security threats, backdoor attacks pose a formidable risk to deep neural networks (DNNs). In recent years, these attacks have grown in sophistication, aiming to compromise the security and integrity of models by clandestinely implanting hidden, unauthorized functionalities or triggers, resulting in deceptive predictions or behaviors. To mitigate the detectability and perceptibility of these triggers, various covert backdoor attack methods have been proposed. However, many of these approaches lack true covert capabilities and are susceptible to manual inspection. Addressing these challenges, this paper introduces a covert backdoor attack method called DEBA. Leveraging the mathematical properties of singular value decomposition (SVD), DEBA embeds minor features of trigger images as backdoors into models during the training phase, thereby causing them to manifest predefined malicious behaviors under specific trigger conditions. Extensive experimental evaluations demonstrate DEBA’s high effectiveness, with poisoned images maintaining high perceptual quality and a commendable attack success rate. Furthermore, the performance of DEBA under existing defense measures is evaluated, revealing its robustness and its significant capability to evade and withstand the impact of these defenses.