Poisoning Attack Detection Method Based on Adaptive Statistical Features

Fenggui Liao, Yongli Wang, Dongmei Liu · 2024

With the wide application of deep learning models in various fields, the issue of model security is getting more and more attention. Poisoning attack is a backdoor trigger implanted in the deep learning model by the attacker by adding malicious data to the training dataset during the model training period, and the attack is activated when a specific poisoned sample is inputted. Poisoning attack, as a kind of highly covert attack, can make the model behave abnormally under specific triggering conditions, and it has been under serious threat in the practical application of the artificial intelligence security field. In order to improve the robustness and accuracy of poisoning attack detection and optimize the computational efficiency, this paper proposes a poisoning attack detection method (ASPD) based on adaptive statistical features. The method optimizes the Gram matrix through a multimodal information fusion model, which can quickly respond to dynamic poisoning attacks, effectively reduce the false alarm rate and improve the detection effect. Based on existing publicly available datasets, ablation study results, and comparisons with the baseline model show that the proposed method improves the recognition accuracy by 0.39%, reduces the false alarm rate by 1.93%, and improves the F1 score by 0.85%. In addition, compared with existing poisoning attack detection methods, this study significantly improves the detection efficiency while reducing the computational resource overhead of high-dimensional features, which provides a new solution to enhance the security of deep learning models and cope with complex poisoning attack scenarios.

Read the paper · More papers on PaperTik