• Home
  • Search
  • Inconspicuous Data Augmentation Based Backdoor Attack on Deep Neural Networks
  • Cite Icon2
  • https://doi.org/10.1109/socc56010.2022.9908113Copy DOI Icon

Inconspicuous Data Augmentation Based Backdoor Attack on Deep Neural Networks

  • Sep 5, 2022
  • Chaohui Xu +4 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

With new applications made possible by the fusion of edge computing and artificial intelligence (AI) technologies, the global market capitalization of edge AI has risen tremendously in recent years. Deployment of pre-trained deep neural network (DNN) models on edge computing platforms, however, does not alleviate the fundamental trust assurance issue arising from the lack of interpretability of end-to-end DNN solutions. The most notorious threat of DNNs is the backdoor attack. Most backdoor attacks require a relatively large injection rate (≈ 10%) to achieve a high attack success rate. The trigger patterns are not always stealthy and can be easily detected or removed by backdoor detectors. Moreover, these attacks are only tested on DNN models implemented on general-purpose computing platforms. This paper proposes to use data augmentation for backdoor attacks to increase the stealth, attack success rate, and robustness. Different data augmentation techniques are applied independently on three color channels to embed a composite trigger. The data augmentation strength is tuned based on the Gradient Magnitude Similarity Deviation, which is used to objectively assess the visual imperceptibility of the poisoned samples. A rich set of composite triggers can be created for different dirty labels. The proposed attacks are evaluated on pre-activation ResNet18 trained with CIFAR-10 and GTSRB datasets, and EfficientNet-B0 trained with adapted 10-class ImageNet dataset. A high attack success rate of above 97% with only 1% injection rate is achieved on these DNN models implemented on both general-purpose computing platforms and Intel Neural Compute Stick 2 edge AI device. The accuracy loss of the poisoned DNNs on benign inputs is kept below 0.6%. The proposed attack is also tested to be resilient to state-of-the-art backdoor defense methods.

Similar Papers
  • Research Article

Industrial software technology: R Mitchell (ed) Peter Peregrinus Ltd (on behalf of the Institution of Electrical Engineers), London, UK (1987) 289pp £37.00

  • May 01, 1989
  • Information and Software Technology
  • R Veryard
  • Conference Article
  • Citations16

Towards Backdoor Attack on Deep Learning based Time Series Classification

  • May 01, 2022
  • Daizong Ding +6
  • PDF
  • Research Article
  • Citations7

Backdoor Attacks on Deep Neural Networks via Transfer Learning from Natural Images

  • Dec 08, 2022
  • Applied Sciences
  • Yuki Matsuo +1
  • Research Article
  • Citations5

Strategic safeguarding: A game theoretic approach for analyzing attacker-defender behavior in DNN backdoors

  • Oct 15, 2024
  • EURASIP Journal on Information Security
  • Kassem Kallas +3
  • Conference Article
  • Citations3

Critical-weight based locking scheme for DNN IP protection in edge computing

  • Sep 30, 2021
  • Ziwei Song +4
  • Conference Article
  • Citations2

Backdoor Filter: Mitigating Visible Backdoor Triggers in Dataset

  • Jul 15, 2021
  • Ziqi Wei +5
  • Research Article
  • Citations5

SSAT: Active Authorization Control and User’s Fingerprint Tracking Framework for DNN IP Protection

  • Oct 29, 2024
  • ACM Transactions on Multimedia Computing, Communications, and Applications
  • Mingfu Xue +5
  • Conference Article
  • Citations36

On decomposing a deep neural network into modules

  • Nov 07, 2020
  • Rangeet Pan +1
  • Research Article
  • Citations8

Backdoor Attacks with Wavelet Embedding: Revealing and enhancing the insights of vulnerabilities in visual object detection models on transformers within digital twin systems

  • Jan 09, 2024
  • Advanced Engineering Informatics
  • Mingkai Shen +1
  • Research Article
  • Citations1

Efficient generation of valid test inputs for deep neural networks via gradient search

  • Mar 28, 2023
  • Journal of Software: Evolution and Process
  • Zhouxian Jiang +2
  • Research Article
  • Citations185

An Empirical Study of the Impact of Hyperparameter Tuning and Model Optimization on the Performance Properties of Deep Neural Networks

  • Apr 09, 2022
  • ACM Transactions on Software Engineering and Methodology
  • Lizhi Liao +3
  • Research Article
  • Citations11

Enhancing deep convolutional neural network models for orange quality classification using MobileNetV2 and data augmentation techniques

  • Jan 01, 2025
  • Journal of Algorithms & Computational Technology
  • Phan Thi Huong +4
  • Conference Article
  • Citations17

Backdoor Attacks on Time Series: A Generative Approach

  • Feb 01, 2023
  • Yujing Jiang +3
  • Book Chapter
  • Citations1

Handwritten Digit Recognition Using Very Deep Convolutional Neural Network

  • Jan 01, 2022
  • M Dhilsath Fathima +2
  • Research Article
  • Citations3

Pure Frequency-Domain Deep Neural Network for IoT-Enabled Smart Cameras

  • Oct 01, 2022
  • IEEE Internet of Things Journal
  • Bo-Yi Wu +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.