Publication: Strategic sample selection for improved clean-label backdoor attacks in text classification
Program
KU-Authors
KU Authors
Co-Authors
Kirci, O. A.
Gursoy, M. E.
Editor & Affiliation
Compiler & Affiliation
Translator
Other Contributor
Date
Language
eng
Embargo Status
N/A
Journal Title
Journal ISSN
Volume Title
Alternative Title
Abstract
Backdoor attacks pose a significant threat to the integrity of text classification models used in natural language processing. While several dirty-label attacks that achieve high attack success rates (ASR) have been proposed, clean-label attacks are inherently more difficult. In this paper, we propose three sample selection strategies to improve attack effectiveness in clean-label scenarios: Minimum, Above50, and Below50. Our strategies identify those samples which the model predicts incorrectly or with low confidence, and by injecting backdoor triggers into such samples, we aim to induce a stronger association between the trigger patterns and the attacker-desired target label. We apply our methods to clean-label variants of four canonical backdoor attacks (InsertSent, WordInj, StyleBkd, SynBkd) and evaluate them on three datasets (IMDB, SST2, HateSpeech) and four model types (LSTM, BERT, DistilBERT, RoBERTa). Results show that the proposed strategies, particularly the Minimum strategy, significantly improve the ASR over random sample selection with little or no degradation in the model’s clean accuracy. Furthermore, clean-label attacks enhanced by our strategies outperform BITE, a state of the art clean-label attack method, in many configurations
Source
Publisher
Springer
Subject
Physical sciences, Computer science, Artificial intelligence, Information systems
Citation
Has Part
Source
Lecture Notes in Computer Science
Book Series Title
Edition
DOI
10.1007/978-3-032-16092-8_22
item.page.datauri
Link
Rights
N/A
Copyrights Note
Creative Commons license
Except where otherwised noted, this item's license is described as N/A
