2603.28824v1 Mar 29, 2026 cs.CR

SNEAKDOOR: 분포 매칭 기반 데이터 응축에 대한 은밀한 백도어 공격

SNEAKDOOR: Stealthy Backdoor Attacks against Distribution Matching-based Dataset Condensation

Dongyi Lv
Dongyi Lv
Citations: 1
h-index: 1
Hee-Jeon Yang
Hee-Jeon Yang
Citations: 0
h-index: 0
Song-Duo Ma
Song-Duo Ma
Citations: 0
h-index: 0
Wei Xi
Wei Xi
Citations: 1
h-index: 1
Jizhong Zhao
Jizhong Zhao
Citations: 170
h-index: 7

데이터 응축은 전체 데이터 세트의 학습 효과를 유지하면서 효율성을 크게 향상시키는, 작고 유용한 데이터 세트를 생성하는 것을 목표로 합니다. 최근 연구에 따르면, 응축 과정은 악의적인 트리거가 응축된 데이터 세트에 삽입되어 추론 과정에서 모델의 동작을 조작하는 백도어 공격에 취약할 수 있습니다. 기존 연구들은 공격 성공률과 클린 테스트 정확도의 균형을 맞추는 데 진전을 이루었지만, 응축된 데이터의 시각적 특징이나 추론 과정에서 발생하는 변화를 숨기는 은밀성을 유지하는 데는 어려움이 있습니다. 이러한 문제를 해결하기 위해, 우리는 공격 효과를 저해하지 않으면서 은밀성을 향상시키는 Sneakdoor를 제안합니다. Sneakdoor는 클래스 결정 경계의 고유한 취약점을 활용하고, 로컬 특징 기하학에 맞춰 입력에 대한 인식을 갖춘 트리거를 생성하는 생성 모듈을 통합하여 검출 가능성을 최소화합니다. 이러한 통합 설계 덕분에 공격은 인간의 시각적 검사 및 통계적 검출 모두에 거의 인지되지 않습니다. 다양한 데이터 세트에서 수행한 광범위한 실험 결과, Sneakdoor는 공격 성공률, 클린 테스트 정확도 및 은밀성 간의 균형을 효과적으로 유지하며, 합성 데이터 및 트리거된 샘플의 보이지 않는 정도를 크게 향상시키는 동시에 높은 공격 효율성을 유지합니다. 코드는 https://github.com/XJTU-AI-Lab/SneakDoor 에서 확인할 수 있습니다.

Original Abstract

Dataset condensation aims to synthesize compact yet informative datasets that retain the training efficacy of full-scale data, offering substantial gains in efficiency. Recent studies reveal that the condensation process can be vulnerable to backdoor attacks, where malicious triggers are injected into the condensation dataset, manipulating model behavior during inference. While prior approaches have made progress in balancing attack success rate and clean test accuracy, they often fall short in preserving stealthiness, especially in concealing the visual artifacts of condensed data or the perturbations introduced during inference. To address this challenge, we introduce Sneakdoor, which enhances stealthiness without compromising attack effectiveness. Sneakdoor exploits the inherent vulnerability of class decision boundaries and incorporates a generative module that constructs input-aware triggers aligned with local feature geometry, thereby minimizing detectability. This joint design enables the attack to remain imperceptible to both human inspection and statistical detection. Extensive experiments across multiple datasets demonstrate that Sneakdoor achieves a compelling balance among attack success rate, clean test accuracy, and stealthiness, substantially improving the invisibility of both the synthetic data and triggered samples while maintaining high attack efficacy. The code is available at https://github.com/XJTU-AI-Lab/SneakDoor.

0 Citations
0 Influential
23.5 Altmetric
0.0 Score
Original PDF
0

No Analysis Report Yet

This paper hasn't been analyzed by Gemini yet.

Log in to request an AI analysis.

댓글

댓글을 작성하려면 로그인하세요.

아직 댓글이 없습니다. 첫 번째 댓글을 남겨보세요!