Vision Transformers (ViTs) have demonstrated the state-of-the-art performance in various vision-related tasks. The success of ViTs motivates adversaries to perform backdoor attacks on ViTs. Although the vulnerability of traditional CNNs to backdoor attacks is well-known, backdoor attacks on ViTs are seldom-studied. Compared to CNNs capturing pixel-wise local features by convolutions, ViTs extract global context information through patches and attentions. Na\"ively transplanting CNN-specific backdoor attacks to ViTs yields only a low clean data accuracy and a low attack success rate. In this paper, we propose a stealth and practical ViT-specific backdoor attack $TrojViT$. Rather than an area-wise trigger used by CNN-specific backdoor attacks, TrojViT generates a patch-wise trigger designed to build a Trojan composed of some vulnerable bits on the parameters of a ViT stored in DRAM memory through patch salience ranking and attention-target loss. TrojViT further uses minimum-tuned parameter update to reduce the bit number of the Trojan. Once the attacker inserts the Trojan into the ViT model by flipping the vulnerable bits, the ViT model still produces normal inference accuracy with benign inputs. But when the attacker embeds a trigger into an input, the ViT model is forced to classify the input to a predefined target class. We show that flipping only few vulnerable bits identified by TrojViT on a ViT model using the well-known RowHammer can transform the model into a backdoored one. We perform extensive experiments of multiple datasets on various ViT models. TrojViT can classify $99.64\%$ of test images to a target class by flipping $345$ bits on a ViT for ImageNet.


翻译:视觉Transformer(ViT)已在各类视觉任务中展现出最先进的性能。ViT的成功促使攻击者对其发起后门攻击。尽管传统卷积神经网络(CNN)易受后门攻击的弱点已广为人知,但针对ViT的后门攻击却鲜有研究。与通过卷积捕获像素级局部特征的CNN不同,ViT通过图像块和注意力机制提取全局上下文信息。将CNN特有的后门攻击简单移植到ViT上,仅能获得较低的干净数据准确率和攻击成功率。本文提出一种隐蔽且实用的ViT专用后门攻击方法$TrojViT$。与CNN专用后门攻击使用的区域级触发器不同,TrojViT生成一种图像块级触发器,通过图像块显著性排序和注意力目标损失,在存储于DRAM中的ViT参数上构建由若干脆弱比特组成的特洛伊木马。TrojViT进一步采用最小调参更新策略,以减少特洛伊木马的比特数量。一旦攻击者通过翻转这些脆弱比特将特洛伊木马植入ViT模型,该模型对良性输入仍能保持正常推理精度;但当攻击者向输入嵌入触发器时,ViT模型将强制将该输入分类至预设目标类别。我们证明,仅需翻转TrojViT识别的少量脆弱比特(利用著名的RowHammer技术),即可将ViT模型转化为带后门模型。我们在多种ViT模型上对多个数据集进行了大量实验。针对ImageNet数据集,TrojViT仅需翻转ViT模型中的$345$个比特,即可使$99.64\%$的测试图像被分类至目标类别。

0
下载
关闭预览

相关内容

ICML2023 | 轻量级视觉Transformer(ViT)的预训练实践手册
专知会员服务
43+阅读 · 2023年5月10日
【ACM Multimedia2021-tutorial】可信赖多媒体分析
专知会员服务
18+阅读 · 2021年10月20日
专知会员服务
30+阅读 · 2021年7月30日
专知会员服务
47+阅读 · 2020年10月31日
一文带你浏览Graph Transformers
极市平台
1+阅读 · 2022年7月12日
VCIP 2022 Call for Demos
CCF多媒体专委会
1+阅读 · 2022年6月6日
BERT/Transformer/迁移学习NLP资源大列表
专知
19+阅读 · 2019年6月9日
Hierarchically Structured Meta-learning
CreateAMind
27+阅读 · 2019年5月22日
强化学习的Unsupervised Meta-Learning
CreateAMind
18+阅读 · 2019年1月7日
【泡泡一分钟】用于评估视觉惯性里程计的TUM VI数据集
泡泡机器人SLAM
11+阅读 · 2019年1月4日
Unsupervised Learning via Meta-Learning
CreateAMind
44+阅读 · 2019年1月3日
A Technical Overview of AI & ML in 2018 & Trends for 2019
待字闺中
18+阅读 · 2018年12月24日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2012年12月31日
国家自然科学基金
1+阅读 · 2012年12月31日
国家自然科学基金
0+阅读 · 2012年12月31日
国家自然科学基金
0+阅读 · 2011年12月31日
Arxiv
0+阅读 · 2023年5月15日
Arxiv
0+阅读 · 2023年5月11日
Arxiv
58+阅读 · 2021年11月15日
Arxiv
39+阅读 · 2021年11月11日
VIP会员
最新内容
致命七类无人机:无人机时代的演进型合成兵种
《异构无人水面艇集群作战自主制导算法》130页
相关基金
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2012年12月31日
国家自然科学基金
1+阅读 · 2012年12月31日
国家自然科学基金
0+阅读 · 2012年12月31日
国家自然科学基金
0+阅读 · 2011年12月31日
Top
微信扫码咨询专知VIP会员