Instance-Agnostic and Practical Clean Label Backdoor Attack Method for Deep Learning Based Face Recognition Models

被引:0
|
作者
Kim, Tae-Hoon [1 ]
Choi, Seok-Hwan [2 ]
Choi, Yoon-Ho [1 ]
机构
[1] Pusan Natl Univ, Sch Comp Sci & Engn, Busan 46241, South Korea
[2] Yonsei Univ, Div Software, Wonju 26493, South Korea
基金
新加坡国家研究基金会;
关键词
Face recognition; Training; Labeling; Deep learning; Steganography; Inspection; Filtering; Artificial neural networks; Data poisoning attack; backdoor attack; deep neural networks (DNNs); security;
D O I
10.1109/ACCESS.2023.3342922
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Backdoor attacks, which induce a trained model to behave as intended by an adversary for specific inputs, have recently emerged as a serious security threat in deep learning-based classification models. In particular, because a backdoor attack is executed solely by incorporating a small quantity of malicious data into a dataset, it poses a significant threat to authentication models, such as facial cognition systems. Depending on whether the label of the poisoned samples has been changed, backdoor attacks on deep learning-based face recognition methods are categorized into one of the two architectures: 1) corrupted label attack; and 2) clean label attack. Clean label attack methods have been actively studied because they can be performed without access to training datasets or training processes. However, the performance of previous clean label attack methods is limited in their application to deep learning-based face recognition methods because they only consider digital triggers with instance-specific characteristics. In this study, we propose a novel clean label backdoor attack, that solves the limitations of the scalability of previous clean label attack methods for deep learning-based face recognition models. To generate poisoned samples that are instance agnostic while including physical triggers, the proposed method applies three core techniques: 1) accessory injection; 2) optimization-based feature transfer; and 3) $N$ :1 mapping for generalization. From the experimental results under various conditions, we demonstrate that the proposed attack method is effective for deep learning-based face recognition models in terms of the attack success rate on unseen samples. We also show that the proposed method not only outperforms the recent clean label attack methods, but also maintains a comparable level of classification accuracy when applied to benign data.
引用
收藏
页码:144040 / 144050
页数:11
相关论文
共 22 条
  • [1] A Practical Clean -Label Backdoor Attack with Limited Information in Vertical Federated Learning
    Chen, Peng
    Yang, Jirui
    Lin, Junxiong
    Lu, Zhihui
    Duan, Qiang
    Chai, Hongfeng
    23RD IEEE INTERNATIONAL CONFERENCE ON DATA MINING, ICDM 2023, 2023, : 41 - 50
  • [2] Clean-label Backdoor Attack on Machine Learning-based Malware Detection Models and Countermeasures
    Zheng, Wanjia
    Omote, Kazumasa
    2022 IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS, TRUSTCOM, 2022, : 1235 - 1242
  • [3] One-to-Multiple Clean-Label Image Camouflage (OmClic) based backdoor attack on deep learning
    Wang, Guohong
    Ma, Hua
    Gao, Yansong
    Abuadbba, Alsharif
    Zhang, Zhi
    Kang, Wei
    Al-Sarawi, Said F.
    Zhang, Gongxuan
    Abbott, Derek
    KNOWLEDGE-BASED SYSTEMS, 2024, 288
  • [4] An Imperceptible Data Augmentation Based Blackbox Clean-Label Backdoor Attack on Deep Neural Networks
    Xu, Chaohui
    Liu, Wenye
    Zheng, Yue
    Wang, Si
    Chang, Chip-Hong
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS I-REGULAR PAPERS, 2023, 70 (12) : 5011 - 5024
  • [5] Multiple Instance Learning with Deep Instance Selection for Video-based Face Recognition
    Liu, Ning
    PROCEEDINGS OF THE 2016 3RD INTERNATIONAL CONFERENCE ON MECHATRONICS AND INFORMATION TECHNOLOGY (ICMIT), 2016, 49 : 327 - 332
  • [6] A Practical Method to Attack Deep Learning Based Host Intrusion Detection Systems
    Zhang, Sicong
    Xie, Xiaoyao
    Xu, Yang
    International Journal of Network Security, 2021, 23 (04) : 663 - 676
  • [7] Deblurring Method of Face Recognition AI Technology Based on Deep Learning
    Li, Weilong
    Li, Jie
    Zhou, Junhui
    ADVANCES IN MULTIMEDIA, 2022, 2022
  • [8] Research on Face Recognition Method Based on Deep Learning in Natural Environment
    Yan, Jiali
    Zhang, Longfei
    Wu, YuFeng
    Guo, Penghui
    Zhang, Fuquan
    Tang, Shuo
    Ding, Gangyi
    Zhang, Fuquan
    Xu, Lin
    2017 IEEE 8TH INTERNATIONAL CONFERENCE ON AWARENESS SCIENCE AND TECHNOLOGY (ICAST), 2017, : 501 - 506
  • [9] Invisible Adversarial Attacks on Deep Learning-Based Face Recognition Models
    Lin, Chih-Yang
    Chen, Feng-Jie
    Ng, Hui-Fuang
    Lin, Wei-Yang
    IEEE ACCESS, 2023, 11 : 51567 - 51577
  • [10] A Study of Deep Learning-Based Face Recognition Models for Sibling Identification
    Goel, Rita
    Mehmood, Irfan
    Ugail, Hassan
    SENSORS, 2021, 21 (15)