Skip to main navigation Skip to search Skip to main content

Training Data Leakage via Imperceptible Backdoor Attack

  • Xiangkai Yang
  • , Wenjian Luo*
  • , Qi Zhou
  • , Zhijian Chen
  • *Corresponding author for this work
  • School of Computer Science and Technology, Harbin Institute of Technology
  • Peng Cheng Laboratory

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Recently, deep neural networks (DNNs) have been widely used and proven successful in many real-world tasks. There are many third-party DNN services available for data holders who want to develop custom DNN applications for their data and tasks. To ensure data privacy, it is crucial to safeguard the data holder's training data. This paper explores a unique attack paradigm where a hostile third-party DNN model supplier subtly obtains training data from the data holder. Prior attacks which can steal training data typically use augmented datasets to memorize the information of the data that the attacker intends to steal. However, these attacks are easily identified since the augmented datasets are visually different from the original dataset and rendered ineffective. In this attack, we generate an augmented dataset by modifying a portion of the training data using the DNN-based image steganography technique. This approach creates an augmented dataset that is visually identical to the original training dataset, making it difficult for humans to detect. Through extensive experiments, we have successfully and quietly accessed the confidential training data of data holders.

Original languageEnglish
Title of host publication2023 IEEE Symposium Series on Computational Intelligence, SSCI 2023
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages1553-1559
Number of pages7
ISBN (Electronic)9781665430654
DOIs
StatePublished - 2023
Externally publishedYes
Event2023 IEEE Symposium Series on Computational Intelligence, SSCI 2023 - Mexico City, Mexico
Duration: 5 Dec 20238 Dec 2023

Publication series

Name2023 IEEE Symposium Series on Computational Intelligence, SSCI 2023

Conference

Conference2023 IEEE Symposium Series on Computational Intelligence, SSCI 2023
Country/TerritoryMexico
CityMexico City
Period5/12/238/12/23

Keywords

  • Deep neural networks
  • backdoor attack
  • data privacy
  • steganography

Fingerprint

Dive into the research topics of 'Training Data Leakage via Imperceptible Backdoor Attack'. Together they form a unique fingerprint.

Cite this