vix.ing · top · new · best · stats · spec

Backdooring Convolutional Neural Networks via Targeted Weight\n Perturbations

2018/12/07 by Jacob Dumford, Dumford, Jacob, Walter J. Scheirer +1 · 7 citations
Computer Science · #Adversarial Robustness in Machine Learning #Advanced Malware Detection Techniques #Network Security and Intrusion Detection

paper · pdf · doi:10.48550/arxiv.1812.03128

Abstract

We present a new type of backdoor attack that exploits a vulnerability of\nconvolutional neural networks (CNNs) that has been previously unstudied. In\nparticular, we examine the application of facial recognition. Deep learning\ntechniques are at the top of the game for facial recognition, which means they\nhave now been implemented in many production-level systems. Alarmingly, unlike\nother commercial technologies such as operating systems and network devices,\ndeep learning-based facial recognition algorithms are not presently designed\nwith security requirements or audited for security vulnerabilities before\ndeployment. Given how young the technology is and how abstract many of the\ninternal workings of these algorithms are, neural network-based facial\nrecognition systems are prime targets for security breaches. As more and more\nof our personal information begins to be guarded by facial recognition (e.g.,\nthe iPhone X), exploring the security vulnerabilities of these systems from a\npenetration testing standpoint is crucial. Along these lines, we describe a\ngeneral methodology for backdooring CNNs via targeted weight perturbations.\nUsing a five-layer CNN and ResNet-50 as case studies, we show that an attacker\nis able to significantly increase the chance that inputs they supply will be\nfalsely accepted by a CNN while simultaneously preserving the error rates for\nlegitimate enrolled classes.\n

Cited by

Related