arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.09047cs.CRcs.CV

多样性至关重要:面向数据高效后门攻击的分布特征覆盖样本选择

Diversity Matters: Distributional Feature Coverage Sample Selection for Data-Efficient Backdoor Attacks

Yi Yang, Xiaoke Chen, Jinyang Huang, Feng-Qi Cui, Yu-Tong Guo, Jia-Cheng Zhao, Haiming Jin, Xiaokang Zhou, Meng Li

首次发表
浏览论文内容

中文总结 AI 辅助

该研究针对低预算脏标签后门攻击,提出无需训练的DFCS方法,通过聚类预训练特征选样,在多个数据集与攻击场景中均实现最高攻击成功率,优于现有方法且保持干净准确率。

中文摘要 AI 辅助

后门攻击会破坏训练数据,使模型保持干净准确率,但在带有触发器的输入上预测攻击者指定的目标。在极低的投毒率下,只有少数样本能传递触发器-目标关联,因此投毒样本的选择至关重要。现有方法通常使用单样本分数对候选样本进行排名,这可能会从相似语义区域中选择冗余样本,且许多方法需要特定于任务的代理训练。我们提出分布特征覆盖样本选择(Distributional Feature Coverage Sample Selection, DFCS),这是一种无需训练、与触发器无关的方法,它将固定预训练特征聚类为每个投毒槽一个区域,并从每个区域中选择最接近质心的样本。局部一阶分析将这种分配与特征覆盖和代表性质量项关联起来。在对 CIFAR-10、Tiny-ImageNet 和 Imagenette 进行 BadNets 和 Blended 攻击的实验中,DFCS 在所有六个数据集-攻击设置中,在七个选择器中实现了最高的平均攻击成功率,平均为 96.30%,在每个设置中比最强的比较方法平均高出 4.60 个百分点,同时保持了干净准确率。这些结果支持分布特征覆盖作为低预算脏标签后门攻击的有效选择原则。

英文摘要

Backdoor attacks compromise training data so that a model retains clean accuracy but predicts an attacker-chosen target on triggered inputs. At very low poisoning rates, only a few samples convey the trigger--target association, making poison-sample selection critical. Existing methods typically rank candidates using per-sample scores, which can select redundant samples from similar semantic regions, and many require task-specific surrogate training. We propose Distributional Feature Coverage Sample Selection (DFCS), a training-free, trigger-agnostic method that clusters fixed pretrained features into one region per poisoning slot and selects the centroid-nearest sample from each region. A local first-order analysis relates this allocation to feature-coverage and representative-mass terms. Across BadNets and Blended attacks on CIFAR-10, Tiny-ImageNet, and Imagenette, DFCS achieves the highest mean attack success rate among seven selectors in all six dataset--attack settings, averaging $96.30\%$ and exceeding the strongest comparator in each setting by 4.60 percentage points on average while preserving clean accuracy. These results support distributional feature coverage as an effective selection principle for low-budget dirty-label backdoor attacks.

发表机构

  • Hefei University of Technology(合肥工业大学)
  • University of Science and Technology of China(中国科学技术大学)
  • Shanghai Jiao Tong University(上海交通大学)
  • Kansai University(关西大学)

机构由 AI 辅助整理,请以论文原文为准。

↑