Stealthy Frequency-Domain Backdoor Attacks: Fourier Decomposition and Fundamental Frequency Injection

10Citations
Citations of this article
5Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

The rising reliance on deep learning models that are black-box in nature is concerning stakeholders about their security in artificial intelligence (AI) applications. Backdoor attacks are a significant challenge due to their ability to remain undetectable. Currently, researchers are focusing on the injection of frequency-domain triggers to enhance the covert nature of these attacks. Nevertheless, this method can introduce uncertain frequency variations that reduce the effectiveness of the attacks. We propose a method for Frequency-Domain Backdoor Attacks in response. The method utilizes Fourier Decomposition and Fundamental Frequency Injection techniques. In our method, we employ Fourier decomposition to mask the fundamental frequency of unsuitable bands, thereby guaranteeing covert trigger injection. As a result, this technique enhances temporal and spectral camouflaging, considerably reducing the likelihood of discovery. Our research contributes to a deeper understanding of backdoor attacks and enhances the security of AI systems by examining this innovative approach. Our approach to AI security centres around exploiting the smooth characteristics of frequencies within the frequency domain. This approach forms the foundation of our work in the field of artificial intelligence security.

Cite

CITATION STYLE

APA

Ma, Q., Qin, J., Yan, K., Wang, L., & Sun, H. (2023). Stealthy Frequency-Domain Backdoor Attacks: Fourier Decomposition and Fundamental Frequency Injection. IEEE Signal Processing Letters, 30, 1677–1681. https://doi.org/10.1109/LSP.2023.3330126

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free