FID筛选和噪声优化的清洁标签后门攻击方法OA
Clean-label backdoor attack method with FID-guided screening and noise optimization
针对现有清洁标签后门攻击普遍忽略不同样本在特征空间的分布差异、常规噪声对样本鲁棒性的削弱不充分等问题,提出一种弗雷歇特感知距离样本筛选和噪声优化的清洁标签后门攻击方法.首先,通过基于特征差异与可识别性约束的样本筛选方法,得到原始数据集中各类别样本的平均特征向量,通过计算各类别中样本的特征向量与平均特征向量的弗雷歇特感知距离,筛选出弗雷歇特感知距离较大且分类损失值低于阈值的样本作为训练样本.然后,采用基于特征偏移驱动的噪声优化方法为筛选出的训练样本添加噪声,在保持样本标签识别准确性的前提下,通过迭代噪声强度,引导样本特征分布向差异持续增大的方向优化,得到优化噪声.最后,在训练样本上注入优化噪声与触发器,生成中毒样本用于训练后门模型并计算清洁标签后门攻击的成功率.实验结果表明,与现有方法相比,在保持良性样本分类准确率几乎不变的情况下,方法对清洁标签后门的攻击成功率指标提升1.71%~14.11%,具有良好的攻击效果.
To address the limitations of existing Clean-Label Backdoor Attack(CLBA)methods,namely,the lack of consideration for sample distribution discrepancies in the feature space and the insufficient weaken-ing of robustness features through conventional noise,this paper proposes a clean-label backdoor attack method with Frechet Inception Distance(FID)-guided sample selection and noise optimization.First,a Sample Selection Method Based on Feature Discrepancy and Recognizability Constraint(FDRC-SSM)is employed to compute the mean feature vector for each class in the dataset.For each sample,the FID between its feature vector and the class mean is calculated.Samples with large FID values and classification losses below a predefined threshold are selected as training candidates.Next,a Noise Optimization Method Driven by Feature Displacement(FDD-NOM)is used to add perturbations to the selected samples.Under the constraint of preserving correct label predictions,the noise intensity is iteratively adjusted to guide the sample feature distribution in the direction of continuously increasing differences,thereby obtaining optimized noise.Finally,optimized noise and a predefined trigger are injected into the selected samples to generate poisoned data,which are used to train the backdoored model.Experimental results demonstrate that,compared with existing approaches,the proposed method achieves a 1.71%to 14.11%improvement in the attack success rate(ASR)while maintaining a nearly unchanged classification accuracy on benign samples,indicating its effectiveness in clean-label backdoor attacks.
谢丽霞;康鹏程;杨宏宇;胡俊成
中国民航大学 计算机科学与技术学院,天津 300300中国民航大学 计算机科学与技术学院,天津 300300中国民航大学 计算机科学与技术学院,天津 300300||中国民航大学 安全科学与工程学院,天津 300300吉林大学 计算机科学与技术学院,吉林 长春 130000
信息技术与安全科学
后门攻击特征提取样本筛选噪声优化
backdoor attackfeature extractionsample selectionnoise optimization
《西安电子科技大学学报(自然科学版)》 2026 (3)
135-150,16
国家自然科学基金民航联合研究基金重点项目(U2433205)
评论