Faculty, Staff and Student Publications

Language

English

Publication Date

1-1-2024

Journal

IEEE Transactions on Emerging Topics in Computing

DOI

10.1109/tetc.2024.3358759

PMID

40256250

PMCID

PMC12007688

PubMedCentral® Posted Date

10-1-2025

PubMedCentral® Full Text Version

Author MSS

Abstract

This work proposes a definition and examines the problem of undetectably engraving special input/output information into a Neural Network (NN). Investigation of this problem is significant given the ubiquity of neural networks and society's reliance on their proper training and use. We systematically study this question and provide (1) definitions of security for secret engravings, (2) machine learning methods for the construction of an engraved network, (3) a threat model that is instantiated with state-of-the-art interpretability methods to devise distinguishers/attackers. In this work, there are two kinds of algorithms. First, the constructions of engravings through machine learning training methods. Second, the distinguishers associated with the threat model. The weakest of our engraved NN constructions are insecure and can be broken by our distinguishers, whereas other, more systematic engravings are resilient to each of our distinguishing attacks on three prototypical image classification datasets. Our threat model is of independent interest, as it provides a concrete quantification/benchmark for the "goodness" of interpretability methods.

Keywords

machine learning, data poisoning, neural net, backdoor attack, security, engraving, interpretability

Published Open-Access

yes

Share

COinS
 
 

To view the content in your browser, please download Adobe Reader or, alternately,
you may Download the file to your hard drive.

NOTE: The latest versions of Adobe Reader do not support viewing PDF files within Firefox on Mac OS and if you are using a modern (Intel) Mac, there is no official plugin for viewing PDF files within the browser window.