MROP:针对深度联合信源信道编码(JSCC)后门攻击的掩码区域优化净化方法
MROP: Mask-Region Optimized Purification Against Backdoor Attack in Deep JSCC
浏览论文内容
中文总结 AI 辅助
针对深度JSCC的输入补丁后门攻击,提出无需重训的MROP方法,通过逐像素掩码优化定位并细化触发区域,在降低攻击成功率的同时保留纯净重构图像的PSNR。
中文摘要 AI 辅助
深度联合信源信道编码(JSCC)通过端到端深度神经网络(DNN)将信源直接映射为信道符号并在接收端重构,以图像传输为应用时,该DNN流水线如同黑箱:当传输图像被破坏时,接收端难以检测安全攻击,从而引入新的安全漏洞。本文研究针对深度JSCC的输入补丁后门攻击防御,该攻击中输入附加的小型触发补丁会迫使解码器输出攻击者选定的目标图像。现有多数补丁触发防御方法针对分类任务,未解决深度JSCC的重构场景。我们将梯度掩码防御适配到该重构场景作为基线,随后提出掩码区域优化净化方法(MROP),该方法在推理阶段运行,无需重新训练JSCC模型。与从输入-输出梯度定位触发的基线不同,MROP在编码器输入处放置逐像素掩码,通过Gumbel-sigmoid松弛优化该掩码以定位触发,随后细化触发区域以更好地重构纯净图像。数值实验在CIFAR-10和STL-10数据集上,结合DeepJSCC和SwinJSCC模型进行评估,结果表明,所提方法在大幅降低攻击成功率(ASR)的同时,保留了纯净重构图像的峰值信噪比(PSNR)。
英文摘要
Deep joint source and channel coding (JSCC) transmits a source by mapping it directly to channel symbols through an end-to-end deep neural network (DNN) and reconstructing it at the receiver. Taking image transmission as an application, this DNN pipeline behaves as a black box: the receiver cannot readily detect security attacks when the transmitted images are corrupted, thereby introducing a new security vulnerability. In this letter, we study defense against input-patch backdoor attacks on deep JSCC, in which a small trigger patch attached to the input forces the decoder to emit an attacker-chosen target image. Most existing patch-trigger defenses are designed for classification, leaving the reconstruction setting of deep JSCC unaddressed. We adapt the gradient mask defense to this reconstruction setting as a baseline and then propose mask-region optimized purification (MROP), which operates at inference and requires no retraining of the JSCC model. Unlike the baseline, which localizes the trigger from the input--output gradient, MROP instead places a per-pixel mask at the encoder input and optimizes it via a Gumbel-sigmoid relaxation to localize the trigger, then refines the trigger region to reconstruct the pure images better. In numerical results, we evaluate the proposed method on CIFAR-10 and STL-10 datasets along with the DeepJSCC and SwinJSCC models. By doing so, we show that the proposed method substantially lowers the attack success rate (ASR) while preserving the peak signal-to-noise ratio (PSNR) of clean reconstructions.
发表机构
- Chungnam National University(忠南国立大学)
- Hanbat National University(韩巴特国立大学)
- Seoul National University(首尔国立大学)
机构由 AI 辅助整理,请以论文原文为准。