发表机构
Northeastern University; Louisiana State University(东北大学; 路易斯安那州立大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究针对视觉MoE的批次依赖令牌调度机制,提出一种三阶段隐蔽供应链后门攻击,在小批次审计时休眠、大批次部署时激活,可规避多种防御,在ImageNet-100等数据集上实现76-87%的攻击成功率。
AI 中文摘要
混合专家(MoE)已成为高效扩展视觉Transformer的主流范式。为确保计算可扩展性并防止专家过载,视觉MoE架构采用了容量受限的令牌调度机制,其中每个专家的处理预算取决于推理批次大小。本研究将这种依赖批次的行为识别为一个被忽视的攻击面,并提出了一种隐蔽的供应链后门攻击,该攻击通过三阶段框架利用这一特性:首先,我们在早期MoE层中注入后门;其次,我们在更深层的MoE层中训练一个中和器,该中和器在正常容量下抑制后门;第三,我们配置一个批次自适应容量因子,该因子为小批次保留高容量,同时为大批次降低容量,在部署规模的批次大小下通过令牌溢出自然禁用中和器。该攻击在小批次安全审计期间处于休眠模式,在大批次部署期间进入激活模式。在ImageNet-100和GTSRB上对V-MoE和Swin-MoE进行的实验表明,激活模式下的攻击成功率为76-87%,休眠模式下的攻击成功率(ASR)低于9%,同时规避了Neural Cleanse、STRIP、Fine-Pruning和Activation Clustering。我们的发现揭示了可扩展视觉MoE架构中依赖批次执行所带来的根本性安全风险。
英文摘要
Mixture-of-Experts (MoE) has become a prevalent paradigm for scaling Vision Transformers efficiently. To ensure computational scalability and prevent expert overload, Vision MoE architectures employ a capacity-bounded token dispatch mechanism, where each expert's processing budget depends on the inference batch size. This work identifies this batch-dependent behavior as an overlooked attack surface, and proposes a stealthy supply-chain backdoor attack that exploits this property through a three-phase framework. First, we inject a backdoor into an early MoE layer. Second, we train a neutralizer in a deeper MoE layer that suppresses the backdoor under normal capacity. Third, we configure a batch-adaptive capacity factor that preserves high capacity for small batches while reducing it for large batches, naturally disabling the neutralizer via token overflow at deployment-scale batch sizes. The attack remains in dormant mode during small-batch security audits and enters activation mode during large-batch deployment. Experiments on V-MoE and Swin-MoE across ImageNet-100 and GTSRB demonstrate activation-mode attack success rates of 76-87% with dormant-mode ASR below 9%, while evading Neural Cleanse, STRIP, Fine-Pruning, and Activation Clustering. Our findings reveal a fundamental security risk arising from batch-dependent execution in scalable Vision MoE architectures.
Comments17 pages, 3 figures, ECCV2026