Presentation 2022-02-28
Basic Study for Backdoor Attack based on Invisible Trigger
Ryo Kumagai, Shu Takemoto, Yusuke Nozaki, Masaya Yoshikawa,
PDF Download Page PDF download Page Link
Abstract(in Japanese) (See Japanese page)
Abstract(in English) A backdoor attack is a threat to deep neural networks (DNN). In an attack on a DNN for the purpose of image classification, an attacker prepares poison data obtained by processing an image of a training data set and contaminates the inference mechanism by mixing it with a label different from the original. In the poison data by the conventional method, it was triggered by dots in inconspicuous places such as the edges of the image. This study propose a backdoor attack method triggered by a pattern that cannot be seen by the naked eye by using a steganography.
Keyword(in Japanese) (See Japanese page)
Keyword(in English) deep neural network / security / backdoor attack / steganography
Paper # AI2021-21
Date of Issue 2022-02-21 (AI)

Conference Information
Committee AI
Conference Date 2022/2/28(1days)
Place (in Japanese) (See Japanese page)
Place (in English) Youth Hostel Sunflower MIYAZAKI
Topics (in Japanese) (See Japanese page)
Topics (in English)
Chair Yuichi Sei(Univ. of Electro-Comm.)
Vice Chair Yuko Sakurai(AIST) / Tadachika Ozono(Nagoya Inst. of Tech.)
Secretary Yuko Sakurai(Tokyo Univ. of Agriculture and Technology) / Tadachika Ozono(Toho Univ.)
Assistant Kazutaka Matsuzaki(Chuo Univ.)

Paper Information
Registration To Technical Committee on Artificial Intelligence and Knowledge-Based Processing
Language JPN
Title (in Japanese) (See Japanese page)
Sub Title (in Japanese) (See Japanese page)
Title (in English) Basic Study for Backdoor Attack based on Invisible Trigger
Sub Title (in English)
Keyword(1) deep neural network
Keyword(2) security
Keyword(3) backdoor attack
Keyword(4) steganography
1st Author's Name Ryo Kumagai
1st Author's Affiliation Meijo University(Meijo Univ.)
2nd Author's Name Shu Takemoto
2nd Author's Affiliation Meijo University(Meijo Univ.)
3rd Author's Name Yusuke Nozaki
3rd Author's Affiliation Meijo University(Meijo Univ.)
4th Author's Name Masaya Yoshikawa
4th Author's Affiliation Meijo University(Meijo Univ.)
Date 2022-02-28
Paper # AI2021-21
Volume (vol) vol.121
Number (no) AI-382
Page pp.pp.53-58(AI),
#Pages 6
Date of Issue 2022-02-21 (AI)