Matches in SemOpenAlex for { <https://semopenalex.org/work/W3217308368> ?p ?o ?g. }
- W3217308368 abstract "Backdoor attacks have been shown to be a serious threat against deep learning systems such as biometric authentication and autonomous driving. An effective backdoor attack could enforce the model misbehave under certain predefined conditions, i.e., triggers, but behave normally otherwise. However, the triggers of existing attacks are directly injected in the pixel space, which tend to be detectable by existing defenses and visually identifiable at both training and inference stages. In this paper, we propose a new backdoor attack FTROJAN through trojaning the frequency domain. The key intuition is that triggering perturbations in the frequency domain correspond to small pixel-wise perturbations dispersed across the entire image, breaking the underlying assumptions of existing defenses and making the poisoning images visually indistinguishable from clean ones. We evaluate FTROJAN in several datasets and tasks showing that it achieves a high attack success rate without significantly degrading the prediction accuracy on benign inputs. Moreover, the poisoning images are nearly invisible and retain high perceptual quality. We also evaluate FTROJAN against state-of-the-art defenses as well as several adaptive defenses that are designed on the frequency domain. The results show that FTROJAN can robustly elude or significantly degenerate the performance of these defenses." @default.
- W3217308368 created "2021-12-06" @default.
- W3217308368 creator A5030118506 @default.
- W3217308368 creator A5030169080 @default.
- W3217308368 creator A5068043486 @default.
- W3217308368 creator A5068080767 @default.
- W3217308368 creator A5068643894 @default.
- W3217308368 creator A5083455588 @default.
- W3217308368 date "2021-11-22" @default.
- W3217308368 modified "2023-10-16" @default.
- W3217308368 title "Backdoor Attack through Frequency Domain" @default.
- W3217308368 cites W1677182931 @default.
- W3217308368 cites W1916685473 @default.
- W3217308368 cites W1959608418 @default.
- W3217308368 cites W1995443851 @default.
- W3217308368 cites W2031614119 @default.
- W3217308368 cites W2056370875 @default.
- W3217308368 cites W2108598243 @default.
- W3217308368 cites W2112796928 @default.
- W3217308368 cites W2114770744 @default.
- W3217308368 cites W2116044718 @default.
- W3217308368 cites W2117876524 @default.
- W3217308368 cites W2133665775 @default.
- W3217308368 cites W2183341477 @default.
- W3217308368 cites W2194775991 @default.
- W3217308368 cites W2535690855 @default.
- W3217308368 cites W2613718673 @default.
- W3217308368 cites W2748789698 @default.
- W3217308368 cites W2774423163 @default.
- W3217308368 cites W2782980316 @default.
- W3217308368 cites W2807363941 @default.
- W3217308368 cites W2810993953 @default.
- W3217308368 cites W2897830718 @default.
- W3217308368 cites W2911634294 @default.
- W3217308368 cites W2914483840 @default.
- W3217308368 cites W2947133760 @default.
- W3217308368 cites W2962858109 @default.
- W3217308368 cites W2963037989 @default.
- W3217308368 cites W2963373786 @default.
- W3217308368 cites W2963384892 @default.
- W3217308368 cites W2963629198 @default.
- W3217308368 cites W2963857521 @default.
- W3217308368 cites W2964041528 @default.
- W3217308368 cites W2966187620 @default.
- W3217308368 cites W2970335439 @default.
- W3217308368 cites W2971028215 @default.
- W3217308368 cites W2985580374 @default.
- W3217308368 cites W2985913519 @default.
- W3217308368 cites W2986013765 @default.
- W3217308368 cites W2990270730 @default.
- W3217308368 cites W2994720379 @default.
- W3217308368 cites W2996757750 @default.
- W3217308368 cites W2996800219 @default.
- W3217308368 cites W3010216907 @default.
- W3217308368 cites W3034175346 @default.
- W3217308368 cites W3034258347 @default.
- W3217308368 cites W3036480850 @default.
- W3217308368 cites W3064006990 @default.
- W3217308368 cites W3081178496 @default.
- W3217308368 cites W3083185154 @default.
- W3217308368 cites W3096024389 @default.
- W3217308368 cites W3096264229 @default.
- W3217308368 cites W3102670879 @default.
- W3217308368 cites W3106646114 @default.
- W3217308368 cites W3107337211 @default.
- W3217308368 cites W3118608800 @default.
- W3217308368 cites W3123680815 @default.
- W3217308368 cites W3128465814 @default.
- W3217308368 doi "https://doi.org/10.48550/arxiv.2111.10991" @default.
- W3217308368 hasPublicationYear "2021" @default.
- W3217308368 type Work @default.
- W3217308368 sameAs 3217308368 @default.
- W3217308368 citedByCount "1" @default.
- W3217308368 countsByYear W32173083682023 @default.
- W3217308368 crossrefType "posted-content" @default.
- W3217308368 hasAuthorship W3217308368A5030118506 @default.
- W3217308368 hasAuthorship W3217308368A5030169080 @default.
- W3217308368 hasAuthorship W3217308368A5068043486 @default.
- W3217308368 hasAuthorship W3217308368A5068080767 @default.
- W3217308368 hasAuthorship W3217308368A5068643894 @default.
- W3217308368 hasAuthorship W3217308368A5083455588 @default.
- W3217308368 hasBestOaLocation W32173083681 @default.
- W3217308368 hasConcept C104317684 @default.
- W3217308368 hasConcept C119857082 @default.
- W3217308368 hasConcept C132010649 @default.
- W3217308368 hasConcept C154945302 @default.
- W3217308368 hasConcept C15744967 @default.
- W3217308368 hasConcept C169760540 @default.
- W3217308368 hasConcept C188147891 @default.
- W3217308368 hasConcept C19118579 @default.
- W3217308368 hasConcept C26517878 @default.
- W3217308368 hasConcept C26760741 @default.
- W3217308368 hasConcept C2776214188 @default.
- W3217308368 hasConcept C2781045450 @default.
- W3217308368 hasConcept C31972630 @default.
- W3217308368 hasConcept C38652104 @default.
- W3217308368 hasConcept C41008148 @default.
- W3217308368 hasConcept C55493867 @default.
- W3217308368 hasConcept C63479239 @default.
- W3217308368 hasConcept C86803240 @default.