Universal Litmus Patterns: Revealing Backdoor Attacks in CNNs. Kolouri, S., Saha, A., Pirsiavash, H., & Hoffmann, H. arXiv:1906.10842 [cs], June, 2019. arXiv: 1906.10842
Universal Litmus Patterns: Revealing Backdoor Attacks in CNNs [link]Paper  abstract   bibtex   
The unprecedented success of deep neural networks in various applications have made these networks a prime target for adversarial exploitation. In this paper, we introduce a benchmark technique for detecting backdoor attacks (aka Trojan attacks) on deep convolutional neural networks (CNNs). We introduce the concept of Universal Litmus Patterns (ULPs), which enable one to reveal backdoor attacks by feeding these universal patterns to the network and analyzing the output (i.e., classifying as `clean' or `corrupted'). This detection is fast because it requires only a few forward passes through a CNN. We demonstrate the effectiveness of ULPs for detecting backdoor attacks on thousands of networks trained on three benchmark datasets, namely the German Traffic Sign Recognition Benchmark (GTSRB), MNIST, and CIFAR10.
@article{kolouri_universal_2019,
	title = {Universal {Litmus} {Patterns}: {Revealing} {Backdoor} {Attacks} in {CNNs}},
	shorttitle = {Universal {Litmus} {Patterns}},
	url = {http://arxiv.org/abs/1906.10842},
	abstract = {The unprecedented success of deep neural networks in various applications have made these networks a prime target for adversarial exploitation. In this paper, we introduce a benchmark technique for detecting backdoor attacks (aka Trojan attacks) on deep convolutional neural networks (CNNs). We introduce the concept of Universal Litmus Patterns (ULPs), which enable one to reveal backdoor attacks by feeding these universal patterns to the network and analyzing the output (i.e., classifying as `clean' or `corrupted'). This detection is fast because it requires only a few forward passes through a CNN. We demonstrate the effectiveness of ULPs for detecting backdoor attacks on thousands of networks trained on three benchmark datasets, namely the German Traffic Sign Recognition Benchmark (GTSRB), MNIST, and CIFAR10.},
	urldate = {2019-07-25},
	journal = {arXiv:1906.10842 [cs]},
	author = {Kolouri, Soheil and Saha, Aniruddha and Pirsiavash, Hamed and Hoffmann, Heiko},
	month = jun,
	year = {2019},
	note = {arXiv: 1906.10842},
	keywords = {\#broken, Computer Science - Computer Vision and Pattern Recognition, Jab/\#Pre, ⛔ No DOI found},
}

Downloads: 0