arXiv · 2007.08273
Deep Learning Backdoors
Abstract
Intuitively, a backdoor attack against Deep Neural Networks (DNNs) is to inject hidden malicious behaviors into DNNs such that the backdoor model behaves legitimately for benign inputs, yet invokes a predefined malicious behavior when its input contains a malicious trigger. The trigger can take a plethora of forms, including a special object present in the image (e.g., a yellow pad), a shape filled with custom textures (e.g., logos with particular colors) or even image-wide stylizations with special filters (e.g., images altered by Nashville or Gotham filters). These filters can be applied to the original image by replacing or perturbing a set of image pixels.
Explore related subjects
Keep this discovery
Shaofeng Li, Shiqing Ma, Minhui Xue, Benjamin Zi Hao Zhao. 2020-07-16. Deep Learning Backdoors. https://arxiv.org/abs/2007.08273
Cite the original work for its findings. Save a collection to share your selection of sources.