A defense method against backdoor attacks on neural networks

被引:7
|
作者
Kaviani, Sara [1 ]
Shamshiri, Samaneh [1 ]
Sohn, Insoo [1 ]
机构
[1] Dongguk Univ, Div Elect & Elect Engn, Seoul, South Korea
基金
新加坡国家研究基金会;
关键词
Feed-forward neural networks; Backdoor attacks; Scale-free networks;
D O I
10.1016/j.eswa.2022.118990
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Due to computational complexities of artificial neural networks (ANNs), there is an increasing demand for third parties and MLaaS (machine learning as a service) to take charge of the training procedure. Therefore, making ANNs robust against adversarial attacks has received a lot of attention. Backdoor attacks, which causes targeted mis-classification while the accuracy on clean data is not affected, are among the most efficient attacks. In this paper, we propose a method called link-pruning with scale-freeness (LPSF), in which the dormant threatening links from the neurons in the input layer to other neurons of feed-forward neural network are eliminated according to the information gained from a portion of clean input data and the essential links are strengthened by changing the fully-connected networks to scale-free structures. To the best of our knowledge, it is the first defense method that makes the network significantly robust against backdoor attack (BD) before the network is attacked. LPSF is evaluated on feed-forward neural networks and with malicious MNIST, FMNIST, handwritten Chinese characters and HODA datasets. Through LPSF strategy, we achieve a sufficiently high and stable accuracy on clean data and an exceeding reduction range of 50% - 94% for attack success rate.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] Interpretability-Guided Defense Against Backdoor Attacks to Deep Neural Networks
    Jiang, Wei
    Wen, Xiangyu
    Zhan, Jinyu
    Wang, Xupeng
    Song, Ziwei
    [J]. IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2022, 41 (08) : 2611 - 2624
  • [2] Verifying Neural Networks Against Backdoor Attacks
    Pham, Long H.
    Sun, Jun
    [J]. COMPUTER AIDED VERIFICATION (CAV 2022), PT I, 2022, 13371 : 171 - 192
  • [3] Defense-Resistant Backdoor Attacks Against Deep Neural Networks in Outsourced Cloud Environment
    Gong, Xueluan
    Chen, Yanjiao
    Wang, Qian
    Huang, Huayang
    Meng, Lingshuo
    Shen, Chao
    Zhang, Qian
    [J]. IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2021, 39 (08) : 2617 - 2631
  • [4] DB-COVIDNet: A Defense Method against Backdoor Attacks
    Shamshiri, Samaneh
    Han, Ki Jin
    Sohn, Insoo
    [J]. MATHEMATICS, 2023, 11 (20)
  • [5] Application of complex systems in neural networks against Backdoor attacks
    Kaviani, Sara
    Sohn, Insoo
    Liu, Huaping
    [J]. 11TH INTERNATIONAL CONFERENCE ON ICT CONVERGENCE: DATA, NETWORK, AND AI IN THE AGE OF UNTACT (ICTC 2020), 2020, : 57 - 59
  • [6] FederatedReverse: A Detection and Defense Method Against Backdoor Attacks in Federated Learning
    Zhao, Chen
    Wen, Yu
    Li, Shuailou
    Liu, Fucheng
    Meng, Dan
    [J]. PROCEEDINGS OF THE 2021 ACM WORKSHOP ON INFORMATION HIDING AND MULTIMEDIA SECURITY, IH&MMSEC 2021, 2021, : 51 - 62
  • [7] Backdoor Attacks to Graph Neural Networks
    Zhang, Zaixi
    Jia, Jinyuan
    Wang, Binghui
    Gong, Neil Zhenqiang
    [J]. PROCEEDINGS OF THE 26TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, SACMAT 2021, 2021, : 15 - 26
  • [8] Backdoor Attacks against Deep Neural Networks by Personalized Audio Steganography
    Liu, Peng
    Zhang, Shuyi
    Yao, Chuanjian
    Ye, Wenzhe
    Li, Xianxian
    [J]. 2022 26TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION (ICPR), 2022, : 68 - 74
  • [9] An Overview of Backdoor Attacks Against Deep Neural Networks and Possible Defences
    Guo, Wei
    Tondi, Benedetta
    Barni, Mauro
    [J]. IEEE OPEN JOURNAL OF SIGNAL PROCESSING, 2022, 3 : 261 - 287
  • [10] Backdoor smoothing: Demystifying backdoor attacks on deep neural networks
    Grosse, Kathrin
    Lee, Taesung
    Biggio, Battista
    Park, Youngja
    Backes, Michael
    Molloy, Ian
    [J]. Computers and Security, 2022, 120