Spectral Signatures in Backdoor Attacks
Name
8024-spectral-signatures-in-backdoor-attacks.pdf
Description
Published version
Size
379.04 KB
Format
Unknown
Checksum (MD5)
87cf45821bda1522432ffc45f7db96c0
Author(s) • •
Tran, Brandon
Li, Jerry
Madry, Aleksander
Date Issued
2018
Citation
Tran, Brandon, Li, Jerry and Madry, Aleksander. 2018. "Spectral Signatures in Backdoor Attacks."
Version
Final published version
Abstract
© 2018 Curran Associates Inc. All rights reserved. A recent line of work has uncovered a new form of data poisoning: so-called backdoor attacks. These attacks are particularly dangerous because they do not affect a network's behavior on typical, benign data. Rather, the network only deviates from its expected output when triggered by a perturbation planted by an adversary. In this paper, we identify a new property of all known backdoor attacks, which we call spectral signatures. This property allows us to utilize tools from robust statistics to thwart the attacks. We demonstrate the efficacy of these signatures in detecting and removing poisoned examples on real image sets and state of the art neural network architectures. We believe that understanding spectral signatures is a crucial first step towards designing ML systems secure against such backdoor attacks.
MIT Department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Terms of Use
Article is made available in accordance with the publisher's policy and may be subject to US copyright law. Please refer to the publisher's site for terms of use.
Persistent DSpace Link
DOI of Published Version
https://papers.nips.cc/paper/8024-spectral-signatures-in-backdoor-attacks