Related Experiment Video
Updated: May 1, 2026

Using Ustilago maydis as a Trojan Horse for In Situ Delivery of Maize Proteins
Published on: February 8, 2019
FeatureTrojan: Boosting stealthy and steady backdoor attacks with feature poisoning and fine-tuning injection
Rui Yang1, Qindong Sun1, Han Cao2
1School of Cyber Science and Engineering, Xi'an Jiaotong University, Xi'an, 710049, China.
None:
Deep neural networks (DNNs) are vulnerable to backdoor attacks, where adversaries can manipulate pre-trained backdoored DNNs and their corresponding applications to produce poisoned outputs when presented with poisoned inputs but behave normally with clean inputs. However, current backdoor attacks in DNNs exhibit certain limitations in terms of stealthiness and steadiness, such as pattern-fixed or even human-perceptible triggers, separated latent space features, and neurons with abnormal behavior. These limitations make them easily detectable or eliminable as backdoor defenses in DNNs advance. To bridge this gap, this paper introduces a novel backdoor attack in DNNs, named FeatureTrojan, which enables pre-trained backdoored DNNs to demonstrate enhanced stealthiness and steadiness. Specifically, unlike previous fixed-pattern triggers that are both human-perceptible and directly added to clean inputs, FeatureTrojan embeds dynamic triggers in latent space features of clean inputs and uses them to guide pre-trained diffusion generative models in generating corresponding poisoned inputs with human-imperceptible triggers. Then, in contrast to retraining pre-trained clean DNNs, FeatureTrojan fine-tunes them, effectively injecting backdoors and producing pre-trained backdoored DNNs while keeping the poisoned parameters close to their clean counterparts. Extensive experiments are conducted on multiple datasets and DNNs to demonstrate that FeatureTrojan can endow pre-trained backdoored DNNs with better stealthiness and steadiness. Compared with the current state-of-the-art backdoor attacks in DNNs, the total average Attack Success Rate (ASR) under various backdoor defenses in DNNs is absolutely improved by ∼ 30.0%. The experimental code is publicly available at https://github.com/Afreadyang/FeatureTrojan.
Related Concept Videos
Leaky Scanning
Defense Mechanism Against Infection
In addition, many body organ systems have unique defenses against infection. The skin is an intact, multilayered surface preventing invasion by microorganisms unless impaired. Mucous membranes lining the mouth, nose, and eyelids are barriers...
Types of Toxins
Air pollutants, primarily gases, pose significant threats to respiratory health, leading to conditions like hypoxia, lung cancer, and in extreme cases, death.
Environmental pollutants like...
Enhanced Elimination of Poison
Antidotes serve a crucial role in counteracting the effects of poison by inhibiting enzymes responsible for producing harmful drug metabolites. In some cases, these toxic metabolites can be neutralized by endogenous cosubstrates, which are maintained at specific concentrations to prevent interaction with cellular macromolecules and subsequent cell death.
Renal excretion is the...
Transduction
Colonisation of Pathogens

