Backdoor Attacks to Deep Learning Models and Countermeasures: A Survey

被引:5
|
作者
Li, Yudong [1 ]
Zhang, Shigeng [1 ,2 ]
Wang, Weiping [1 ]
Song, Hong [1 ]
机构
[1] Cent South Univ, Sch Comp Sci & Engn, Changsha 410083, Peoples R China
[2] Parallel & Distributed Proc Lab PDL Changsha, Sci & Technol, Changsha 410003, Peoples R China
来源
IEEE OPEN JOURNAL OF THE COMPUTER SOCIETY | 2023年 / 4卷
关键词
Deep learning; Face recognition; Data models; Computational modeling; Training; Perturbation methods; Video on demand; security; backdoor attack;
D O I
10.1109/OJCS.2023.3267221
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Backdoor attacks have severely threatened deep neural network (DNN) models in the past several years. In backdoor attacks, the attackers try to plant hidden backdoors into DNN models, either in the training or inference stage, to mislead the output of the model when the input contains some specified triggers without affecting the prediction of normal inputs not containing the triggers. As a rapidly developing topic, numerous works on designing various backdoor attacks and developing techniques to defend against such attacks have been proposed in recent years. However, a comprehensive and holistic overview of backdoor attacks and countermeasures is still missing. In this paper, we provide a systematic overview of the design of backdoor attacks and the defense strategies to defend against backdoor attacks, covering the latest published works. We review representative backdoor attacks and defense strategies in both the computer vision domain and other domains, discuss their pros and cons, and make comparisons among them. We outline key challenges to be addressed and potential research directions in the future.
引用
收藏
页码:134 / 146
页数:13
相关论文
共 50 条
  • [41] Deep learning countermeasures for detecting replay speech attacks: a review
    Suresh Veesa
    Madhusudan Singh
    International Journal of Speech Technology, 2025, 28 (1) : 39 - 51
  • [42] EEG-Based Brain-Computer Interfaces are Vulnerable to Backdoor Attacks
    Meng, Lubin
    Jiang, Xue
    Huang, Jian
    Zeng, Zhigang
    Yu, Shan
    Jung, Tzyy-Ping
    Lin, Chin-Teng
    Chavarriaga, Ricardo
    Wu, Dongrui
    IEEE TRANSACTIONS ON NEURAL SYSTEMS AND REHABILITATION ENGINEERING, 2023, 31 : 2224 - 2234
  • [43] Towards defending adaptive backdoor attacks in Federated Learning
    Yang, Han
    Gu, Dongbing
    He, Jianhua
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 5078 - 5084
  • [44] A Comprehensive Survey on Backdoor Attacks and Their Defenses in Face Recognition Systems
    Le Roux, Quentin
    Bourbao, Eric
    Teglia, Yannick
    Kallas, Kassem
    IEEE ACCESS, 2024, 12 : 47433 - 47468
  • [45] Unlearning Backdoor Attacks in Federated Learning
    Wu, Chen
    Zhu, Sencun
    Mitra, Prasenjit
    Wang, Wei
    2024 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY, CNS 2024, 2024,
  • [46] Backdoor attacks and defenses in federated learning: Survey, challenges and future research directions
    Nguyen, Thuy Dung
    Nguyen, Tuan
    Nguyen, Phi Le
    Pham, Hieu H.
    Doan, Khoa D.
    Wong, Kok-Seng
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2024, 127
  • [47] Stealthy Targeted Backdoor Attacks Against Image Captioning
    Fan, Wenshu
    Li, Hongwei
    Jiang, Wenbo
    Hao, Meng
    Yu, Shui
    Zhang, Xiao
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 5655 - 5667
  • [48] A Survey of Adversarial Attacks: An Open Issue for Deep Learning Sentiment Analysis Models
    Vazquez-Hernandez, Monserrat
    Morales-Rosales, Luis Alberto
    Algredo-Badillo, Ignacio
    Fernandez-Gregorio, Sofia Isabel
    Rodriguez-Rangel, Hector
    Cordoba-Tlaxcalteco, Maria-Luisa
    APPLIED SCIENCES-BASEL, 2024, 14 (11):
  • [49] Deep Learning for Securing Software-Defined Industrial Internet of Things: Attacks and Countermeasures
    Wang, Jiadai
    Liu, Jiajia
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (13) : 11179 - 11189
  • [50] Invisible Adversarial Attacks on Deep Learning-Based Face Recognition Models
    Lin, Chih-Yang
    Chen, Feng-Jie
    Ng, Hui-Fuang
    Lin, Wei-Yang
    IEEE ACCESS, 2023, 11 : 51567 - 51577