Low-ASR Backdoors: Exploiting Attack Success Rate Reduction and Attacker-Defender Asymmetry

📅 2026-08-27
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文针对深度学习中高攻击成功率的后门攻击假设,提出一种逆向训练框架,生成低ASR后门模型,揭示现有防御机制的弱点。
📝 Abstract
Backdoor attacks are among the most effective and stealthy attacks in deep learning. Existing attacks and defenses are largely designed and evaluated under the assumption that successful backdoors exhibit high Attack Success Rates (ASRs). In this paper, we show that this assumption creates a fundamental weakness in existing defense paradigms. ASR is not an intrinsic property of a backdoor; rather, it is an attacker-controlled variable that can be deliberately reduced without eliminating the underlying backdoor behavior. We introduce a reverse-training framework that weakens the trigger-target association, producing low-ASR backdoor models while preserving clean-input performance. Through extensive evaluation across multiple datasets, diverse attack families, and multiple architectures, we show that state-of-the-art defenses fail consistently under low-ASR conditions, exposing a fundamental attacker-defender asymmetry.
Problem

Research questions and friction points this paper is trying to address.

backdoor attacks
attack success rate
defenses
asymmetry
deep learning
Innovation

Methods, ideas, or system contributions that make the work stand out.

Low-ASR Backdoors
reverse-training framework
attacker-defender asymmetry
🔎 Similar Papers
No similar papers found.