TY - GEN
T1 - FREEEAGLE
T2 - 32nd USENIX Security Symposium, USENIX Security 2023
AU - Fu, Chong
AU - Zhang, Xuhong
AU - Ji, Shouling
AU - Wang, Ting
AU - Lin, Peng
AU - Feng, Yanghe
AU - Yin, Jianwei
N1 - Publisher Copyright:
© 2023 32nd USENIX Security Symposium, USENIX Security 2023. All rights reserved.
PY - 2023
Y1 - 2023
N2 - Trojan attack on deep neural networks, also known as backdoor attack, is a typical threat to artificial intelligence. A trojaned neural network behaves normally with clean inputs. However, if the input contains a particular trigger, the trojaned model will have attacker-chosen abnormal behavior. Although many backdoor detection methods exist, most of them assume that the defender has access to a set of clean validation samples or samples with the trigger, which may not hold in some crucial real-world cases, e.g., the case where the defender is the maintainer of model-sharing platforms. Thus, in this paper, we propose FREEEAGLE, the first data-free backdoor detection method that can effectively detect complex backdoor attacks on deep neural networks, without relying on the access to any clean samples or samples with the trigger. The evaluation results on diverse datasets and model architectures show that FREEEAGLE is effective against various complex backdoor attacks, even outperforming some state-of-the-art non-data-free backdoor detection methods.
AB - Trojan attack on deep neural networks, also known as backdoor attack, is a typical threat to artificial intelligence. A trojaned neural network behaves normally with clean inputs. However, if the input contains a particular trigger, the trojaned model will have attacker-chosen abnormal behavior. Although many backdoor detection methods exist, most of them assume that the defender has access to a set of clean validation samples or samples with the trigger, which may not hold in some crucial real-world cases, e.g., the case where the defender is the maintainer of model-sharing platforms. Thus, in this paper, we propose FREEEAGLE, the first data-free backdoor detection method that can effectively detect complex backdoor attacks on deep neural networks, without relying on the access to any clean samples or samples with the trigger. The evaluation results on diverse datasets and model architectures show that FREEEAGLE is effective against various complex backdoor attacks, even outperforming some state-of-the-art non-data-free backdoor detection methods.
UR - https://www.scopus.com/pages/publications/85176111209
M3 - Conference contribution
AN - SCOPUS:85176111209
T3 - 32nd USENIX Security Symposium, USENIX Security 2023
SP - 6399
EP - 6416
BT - 32nd USENIX Security Symposium, USENIX Security 2023
PB - USENIX Association
Y2 - 9 August 2023 through 11 August 2023
ER -