arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

低攻击成功率后门:利用攻击成功率降低与攻防不对称性

Low-ASR Backdoors: Exploiting Attack Success Rate Reduction and Attacker-Defender Asymmetry

Arham Riaz, Ting Yu

arXiv 2608.27288首次发表:更新:

AI 中文总结

本文提出反向训练框架生成低攻击成功率后门,发现现有防御在低ASR条件下失效,揭示了攻防不对称性,为后门攻击与防御研究提供新视角。

AI 中文摘要

后门攻击是深度学习中最有效且隐蔽的攻击类型之一。现有攻击与防御方法大多在“成功后门具有高攻击成功率(ASR)”的假设下设计与评估。本文表明,该假设在现有防御范式中存在根本性缺陷:ASR并非后门的固有属性,而是攻击者可控变量,可在不消除后门行为的情况下刻意降低。我们提出一种反向训练框架,弱化触发器-目标关联,生成低ASR后门模型同时保留干净输入性能。通过在多数据集、多攻击族、多架构上的广泛评估,我们发现最先进的防御在低ASR条件下持续失效,暴露了根本性的攻防不对称性。

英文摘要

Backdoor attacks are among the most effective and stealthy attacks in deep learning. Existing attacks and defenses are largely designed and evaluated under the assumption that successful backdoors exhibit high Attack Success Rates (ASRs). In this paper, we show that this assumption creates a fundamental weakness in existing defense paradigms. ASR is not an intrinsic property of a backdoor; rather, it is an attacker-controlled variable that can be deliberately reduced without eliminating the underlying backdoor behavior. We introduce a reverse-training framework that weakens the trigger-target association, producing low-ASR backdoor models while preserving clean-input performance. Through extensive evaluation across multiple datasets, diverse attack families, and multiple architectures, we show that state-of-the-art defenses fail consistently under low-ASR conditions, exposing a fundamental attacker-defender asymmetry.

Comments25 page, 16 main, 9 appendix

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑