答案在于:通过DNN固有的特征检测木马
Xuchao Liu1, Qi Cao1, Kaike Zhang1
1Institute of Computing Technology, Chinese Academy of Sciences, Zhongguancun, Haidian District, Beijing, 100190, Beijing, China.
概括
这项研究引入了一种新方法,用于在深度神经网络 (DNN) 中检测特洛伊木马攻击,而不需要良性样本. 这种方法被称为从DNN检测特洛伊木马.
科学领域:
- 人工智能的人工智能
- 机器学习安全 机器学习安全
背景情况:
- 深度神经网络 (DNN) 容易受到特洛伊木马攻击,恶意触发器会导致它们发生故障.
- 现有的特洛伊木马检测方法通常依赖于良性样本和耗时的优化,限制了它们的实际使用.
- 良性无样本场景对强大的木马检测构成了重大挑战.
研究的目的:
- 开发一种有效和可通用的方法来检测DNN中的木马,而不需要良性样本.
- 在实际应用中解决传统触发器倒置技术的局限性.
主要方法:
- 建议通过DNN固有的特征 (DTIC) 检测特洛伊木马,这是一种利用特洛伊木马模型独特特征的新方法.
- DTIC利用了从DNN结构和参数获得的统一表示空间,以便在各种模型中进行适应.
- 该方法使用随机扰动和彩票假设来提高检测性能.
主要成果:
- DTIC实现了高效率,只需要一次直接推断来检测木马.
- 在IARPA TrajAI基准上的实验证明了DTIC的卓越有效性和通用性.
- 拟议的方法在具有挑战性的良性无样本场景中成功运行.
结论:
- 在DNN的特洛伊木马检测方面,DTIC提供了显著的进步,克服了以前方法的局限性.
- 该方法提供了一种高效,有效和可通用的解决方案,用于保护DNN免受特洛伊木马攻击.
- 这项工作为在现实应用中更可靠的DNN安全铺平了道路.
相关概念视频
Methods of Classification and Identification
1.0K
Bacterial identification relies on a diverse array of techniques to classify and understand microorganisms, each tailored to uncover specific characteristics. Traditional morphological approaches, while still valuable, are limited for closely related or structurally simple organisms. Modern methods integrate biochemical, serological, genetic, and advanced molecular tools to achieve greater accuracy.Morphological and Biochemical TechniquesMorphological characteristics, such as cell shape and...
1.0K
Viruses with RNA Genomes
824
RNA viruses are categorized into positive-strand, negative-strand, or double-stranded groups based on their genomic structure and replication mechanisms. This classification dictates how they exploit host cellular machinery for protein synthesis and replication. Some RNA viruses also utilize reverse transcription as part of their life cycle, further diversifying their replication strategies.Positive-Strand RNA VirusesPositive-strand RNA viruses have genomes that function directly as messenger...
824


