vix.ing · top · new · best · stats

Breaking the Stealth-Potency Trade-off in Clean-Image Backdoors with Generative Trigger Optimization

2025/11/10 by Binyan Xu, Xu, Binyan, Fan Yang +7 · 1 citation
Computer Science · #Advanced Malware Detection Techniques #Adversarial Robustness in Machine Learning #Backdoor #Deep learning #Generative grammar #Obstacle #Resilience (materials science) #Security and Verification in Computing #Set (abstract data type) #Training set #Trojan #acm:68T07 #cs.CR #cs.CV #cs.LG #msc:68T07

paper · pdf · open access · doi:10.48550/arxiv.2511.07210

published in arXiv (Cornell University) (Cornell University) · 19 pages, 22 figures, 15 tables. To appear in AAAI '26 (Oral). This paper extends the AAAI-2026 version by including the Appendix

openalex publication_date 2025/11/10 · openalex created_date 2025/11/12 · openalex updated_date 2026/07/28 · arxiv created 2026/07/29 · arxiv updated 2026/07/30

Abstract

Clean-image backdoor attacks, which use only label manipulation in training datasets to compromise deep neural networks, pose a significant threat to security-critical applications. A critical flaw in existing methods is that the poison rate required for a successful attack induces a proportional, and thus noticeable, drop in Clean Accuracy (CA), undermining their stealthiness. This paper presents a new paradigm for clean-image attacks that minimizes this accuracy degradation by optimizing the trigger itself. We introduce Generative Clean-Image Backdoors (GCB), a framework that uses a conditional InfoGAN to identify naturally occurring image features that can serve as potent and stealthy triggers. By ensuring these triggers are easily separable from benign task-related features, GCB enables a victim model to learn the backdoor from an extremely small set of poisoned examples, resulting in a CA drop of less than 1%. Our experiments demonstrate GCB's remarkable versatility, successfully adapting to six datasets, five architectures, and four tasks, including the first demonstration of clean-image backdoors in regression and segmentation. GCB also exhibits resilience against most of the existing backdoor defenses.

Citations

Cited by

Related