TriMPA: Triggerless Targeted Model Poisoning Attack in DNN
Debasmita Manna, Somanath Tripathy · IEEE Transactions on Computational Social Systems · 2024
Due to its admirable accuracy and performance across a wide range of classification and identification tasks, deep learning algorithms have gained popularity in several applications. However, the models’ security has become a serious concern, as antagonists could use them to promote their malicious goals. This work proposes a triggerless targeted model poisoning attack (TriMPA) against deep neural network without requiring any change in input to trigger the backdoor. TriMPA identifies active neurons that highly contribute to the prediction of the victim output label and replaces those neurons with that corresponding to the target output label. The performance of the proposed mechanism is evaluated through experiments as well as analyzed theoretically. It is shown that TriMPA achieves a higher attack success rate.