TY - GEN
T1 - Training Data Leakage via Imperceptible Backdoor Attack
AU - Yang, Xiangkai
AU - Luo, Wenjian
AU - Zhou, Qi
AU - Chen, Zhijian
N1 - Publisher Copyright:
© 2023 IEEE.
PY - 2023
Y1 - 2023
N2 - Recently, deep neural networks (DNNs) have been widely used and proven successful in many real-world tasks. There are many third-party DNN services available for data holders who want to develop custom DNN applications for their data and tasks. To ensure data privacy, it is crucial to safeguard the data holder's training data. This paper explores a unique attack paradigm where a hostile third-party DNN model supplier subtly obtains training data from the data holder. Prior attacks which can steal training data typically use augmented datasets to memorize the information of the data that the attacker intends to steal. However, these attacks are easily identified since the augmented datasets are visually different from the original dataset and rendered ineffective. In this attack, we generate an augmented dataset by modifying a portion of the training data using the DNN-based image steganography technique. This approach creates an augmented dataset that is visually identical to the original training dataset, making it difficult for humans to detect. Through extensive experiments, we have successfully and quietly accessed the confidential training data of data holders.
AB - Recently, deep neural networks (DNNs) have been widely used and proven successful in many real-world tasks. There are many third-party DNN services available for data holders who want to develop custom DNN applications for their data and tasks. To ensure data privacy, it is crucial to safeguard the data holder's training data. This paper explores a unique attack paradigm where a hostile third-party DNN model supplier subtly obtains training data from the data holder. Prior attacks which can steal training data typically use augmented datasets to memorize the information of the data that the attacker intends to steal. However, these attacks are easily identified since the augmented datasets are visually different from the original dataset and rendered ineffective. In this attack, we generate an augmented dataset by modifying a portion of the training data using the DNN-based image steganography technique. This approach creates an augmented dataset that is visually identical to the original training dataset, making it difficult for humans to detect. Through extensive experiments, we have successfully and quietly accessed the confidential training data of data holders.
KW - Deep neural networks
KW - backdoor attack
KW - data privacy
KW - steganography
UR - https://www.scopus.com/pages/publications/85182917231
U2 - 10.1109/SSCI52147.2023.10372011
DO - 10.1109/SSCI52147.2023.10372011
M3 - 会议稿件
AN - SCOPUS:85182917231
T3 - 2023 IEEE Symposium Series on Computational Intelligence, SSCI 2023
SP - 1553
EP - 1559
BT - 2023 IEEE Symposium Series on Computational Intelligence, SSCI 2023
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2023 IEEE Symposium Series on Computational Intelligence, SSCI 2023
Y2 - 5 December 2023 through 8 December 2023
ER -