Matches in SemOpenAlex for { <https://semopenalex.org/work/W4313483989> ?p ?o ?g. }
Showing items 1 to 57 of
57
with 100 items per page.
- W4313483989 abstract "Wild images on the web are vulnerable to backdoor (also called trojan) poisoning, causing machine learning models learned on these images to be injected with backdoors. Most previous attacks assumed that the wild images are labeled. In reality, however, most images on the web are unlabeled. Specifically, we study the effects of unlabeled backdoor images under semi-supervised learning (SSL) on widely studied deep neural networks. To be realistic, we assume that the adversary is zero-knowledge and that the semi-supervised learning model is trained from scratch. Firstly, we find the fact that backdoor poisoning always fails when poisoned unlabeled images come from different classes, which is different from poisoning the labeled images. The reason is that the SSL algorithms always strive to correct them during training. Therefore, for unlabeled images, we implement backdoor poisoning on images from the target class. Then, we propose a gradient matching strategy to craft poisoned images such that their gradients match the gradients of target images on the SSL model, which can fit poisoned images to the target class and realize backdoor injection. To the best of our knowledge, this may be the first approach to backdoor poisoning on unlabeled images of trained-from-scratch SSL models. Experiments show that our poisoning achieves state-of-the-art attack success rates on most SSL algorithms while bypassing modern backdoor defenses." @default.
- W4313483989 created "2023-01-06" @default.
- W4313483989 creator A5026512168 @default.
- W4313483989 creator A5039487331 @default.
- W4313483989 creator A5054324316 @default.
- W4313483989 creator A5071724015 @default.
- W4313483989 date "2023-01-01" @default.
- W4313483989 modified "2023-09-26" @default.
- W4313483989 title "Trojaning semi-supervised learning model via poisoning wild images on the web" @default.
- W4313483989 doi "https://doi.org/10.48550/arxiv.2301.00435" @default.
- W4313483989 hasPublicationYear "2023" @default.
- W4313483989 type Work @default.
- W4313483989 citedByCount "0" @default.
- W4313483989 crossrefType "posted-content" @default.
- W4313483989 hasAuthorship W4313483989A5026512168 @default.
- W4313483989 hasAuthorship W4313483989A5039487331 @default.
- W4313483989 hasAuthorship W4313483989A5054324316 @default.
- W4313483989 hasAuthorship W4313483989A5071724015 @default.
- W4313483989 hasBestOaLocation W43134839891 @default.
- W4313483989 hasConcept C108583219 @default.
- W4313483989 hasConcept C115961682 @default.
- W4313483989 hasConcept C119857082 @default.
- W4313483989 hasConcept C153180895 @default.
- W4313483989 hasConcept C154945302 @default.
- W4313483989 hasConcept C174333608 @default.
- W4313483989 hasConcept C2777212361 @default.
- W4313483989 hasConcept C2781045450 @default.
- W4313483989 hasConcept C31972630 @default.
- W4313483989 hasConcept C38652104 @default.
- W4313483989 hasConcept C41008148 @default.
- W4313483989 hasConceptScore W4313483989C108583219 @default.
- W4313483989 hasConceptScore W4313483989C115961682 @default.
- W4313483989 hasConceptScore W4313483989C119857082 @default.
- W4313483989 hasConceptScore W4313483989C153180895 @default.
- W4313483989 hasConceptScore W4313483989C154945302 @default.
- W4313483989 hasConceptScore W4313483989C174333608 @default.
- W4313483989 hasConceptScore W4313483989C2777212361 @default.
- W4313483989 hasConceptScore W4313483989C2781045450 @default.
- W4313483989 hasConceptScore W4313483989C31972630 @default.
- W4313483989 hasConceptScore W4313483989C38652104 @default.
- W4313483989 hasConceptScore W4313483989C41008148 @default.
- W4313483989 hasLocation W43134839891 @default.
- W4313483989 hasOpenAccess W4313483989 @default.
- W4313483989 hasPrimaryLocation W43134839891 @default.
- W4313483989 hasRelatedWork W2773120646 @default.
- W4313483989 hasRelatedWork W3014300295 @default.
- W4313483989 hasRelatedWork W3164822677 @default.
- W4313483989 hasRelatedWork W3215138031 @default.
- W4313483989 hasRelatedWork W4223943233 @default.
- W4313483989 hasRelatedWork W4225161397 @default.
- W4313483989 hasRelatedWork W4250304930 @default.
- W4313483989 hasRelatedWork W4299487748 @default.
- W4313483989 hasRelatedWork W4309045103 @default.
- W4313483989 hasRelatedWork W4312200629 @default.
- W4313483989 isParatext "false" @default.
- W4313483989 isRetracted "false" @default.
- W4313483989 workType "article" @default.