{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/targeted-backdoor-attacks-on-deep-learning","title":"Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning","arxiv_id":"1712.05526","date":"2017-12-15","proceeding":null,"authors":["Xinyun Chen","Chang Liu","Bo Li","Kimberly Lu","Dawn Song"],"abstract":"Deep learning models have achieved high performance on many tasks, and thus\nhave been applied to many security-critical scenarios. For example, deep\nlearning-based face recognition systems have been used to authenticate users to\naccess many security-sensitive applications like payment apps. Such usages of\ndeep learning systems provide the adversaries with sufficient incentives to\nperform attacks against these systems for their adversarial purposes. In this\nwork, we consider a new type of attacks, called backdoor attacks, where the\nattacker's goal is to create a backdoor into a learning-based authentication\nsystem, so that he can easily circumvent the system by leveraging the backdoor.\nSpecifically, the adversary aims at creating backdoor instances, so that the\nvictim learning system will be misled to classify the backdoor instances as a\ntarget label specified by the adversary. In particular, we study backdoor\npoisoning attacks, which achieve backdoor attacks using poisoning strategies.\nDifferent from all existing work, our studied poisoning strategies can apply\nunder a very weak threat model: (1) the adversary has no knowledge of the model\nand the training set used by the victim system; (2) the attacker is allowed to\ninject only a small amount of poisoning samples; (3) the backdoor key is hard\nto notice even by human beings to achieve stealthiness. We conduct evaluation\nto demonstrate that a backdoor adversary can inject only around 50 poisoning\nsamples, while achieving an attack success rate of above 90%. We are also the\nfirst work to show that a data poisoning attack can create physically\nimplementable backdoors without touching the training process. Our work\ndemonstrates that backdoor poisoning attacks pose real threats to a learning\nsystem, and thus highlights the importance of further investigation and\nproposing defense strategies against them.","url_abs":"http://arxiv.org/abs/1712.05526v1","url_pdf":"http://arxiv.org/pdf/1712.05526v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"targeted-backdoor-attacks-on-deep-learning","repo_url":"https://github.com/bxz9200/ultraclean","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}}],"tasks":[{"task_slug":"data-poisoning","task_name":"Data Poisoning"},{"task_slug":"deep-learning","task_name":"Deep Learning"},{"task_slug":"face-recognition","task_name":"Face Recognition"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1712.05526","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}