{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/poison-ink-robust-and-invisible-backdoor","title":"Poison Ink: Robust and Invisible Backdoor Attack","arxiv_id":"2108.02488","date":"2021-08-05","proceeding":null,"authors":["Jie Zhang","Dongdong Chen","Qidong Huang","Jing Liao","Weiming Zhang","Huamin Feng","Gang Hua","Nenghai Yu"],"abstract":"Recent research shows deep neural networks are vulnerable to different types of attacks, such as adversarial attack, data poisoning attack and backdoor attack. Among them, backdoor attack is the most cunning one and can occur in almost every stage of deep learning pipeline. Therefore, backdoor attack has attracted lots of interests from both academia and industry. However, most existing backdoor attack methods are either visible or fragile to some effortless pre-processing such as common data transformations. To address these limitations, we propose a robust and invisible backdoor attack called \"Poison Ink\". Concretely, we first leverage the image structures as target poisoning areas, and fill them with poison ink (information) to generate the trigger pattern. As the image structure can keep its semantic meaning during the data transformation, such trigger pattern is inherently robust to data transformations. Then we leverage a deep injection network to embed such trigger pattern into the cover image to achieve stealthiness. Compared to existing popular backdoor attack methods, Poison Ink outperforms both in stealthiness and robustness. Through extensive experiments, we demonstrate Poison Ink is not only general to different datasets and network architectures, but also flexible for different attack scenarios. Besides, it also has very strong resistance against many state-of-the-art defense techniques.","url_abs":"https://arxiv.org/abs/2108.02488v3","url_pdf":"https://arxiv.org/pdf/2108.02488v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"poison-ink-robust-and-invisible-backdoor","repo_url":"https://github.com/ZJZAC/Poison-Ink","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"},{"task_slug":"backdoor-attack","task_name":"Backdoor Attack"},{"task_slug":"data-poisoning","task_name":"Data Poisoning"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2108.02488","atlas_url":"https://app.syntology.ai/?focus=2108.02488","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2108.02488"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/ZJZAC/Poison-Ink","reach":null}],"summary":{"ran_fixture":1,"unverified":1},"by_repo_kind":{"listed":{"samples":2,"ran":1,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"f9d6b29bf5d86ee0","entry":"F_batch_bilinear_interp2d","repo":"ZJZAC/Poison-Ink","repo_kind":"listed","path":"trigger_generation/IN_GE.py","file_url":"https://github.com/ZJZAC/Poison-Ink/blob/HEAD/trigger_generation/IN_GE.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"f9d6b29bf5d86ee0"}},{"code_sha256_prefix":"926a8f4c89f6c8da","entry":"F_batch_affine2d","repo":"ZJZAC/Poison-Ink","repo_kind":"listed","path":"trigger_generation/IN_GE.py","file_url":"https://github.com/ZJZAC/Poison-Ink/blob/HEAD/trigger_generation/IN_GE.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"926a8f4c89f6c8da"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}