PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 10, 2026Electronics0 citationsOpen Access

Ditto: An Adaptable and Highly Robust Invisible Backdoor Attack Towards Deep Neural Networks

View Full Paper
WZWenhao ZhangLZLianheng ZouYXYingying Xiong

Key Points

  • This research aims to develop a robust and adaptable backdoor attack method called Ditto for deep neural networks.
  • Utilizes a boundary detection algorithm to find trigger insertion points.
  • Implements a padding algorithm to enhance trigger stealthiness.
  • Generates dynamic triggers using a generative adversarial network based on image texture features.
  • Adjusts the stealthiness level of the embedded trigger before application.
  • Tests the attack's effectiveness against several backdoor defense techniques.
  • Achieves a high level of stealthiness compared to existing backdoor attacks.
  • Maintains a high attack success rate during experimentation.
  • Shows strong accuracy on clean data despite the backdoor insertion.
  • Demonstrates significant robustness against standard baseline defense techniques.

Abstract

With the widespread application of deep neural networks across various fields, issues related to model security have become increasingly prevalent. Backdoor attacks, as a covert method of attack, can implant malicious behavior during the model training process, causing the model to perform predetermined tasks under specific trigger conditions. However, current backdoor attacks struggle to achieve a good balance between stealthiness and attack success rate, and there is an issue in which certain data transformation operations can negatively impact attack performance. To address these issues, this paper proposes a specialized backdoor attack method called Ditto. It first uses a boundary detection algorithm and a padding algorithm to determine the trigger’s insertion position. The trigger is then dynamically generated using a generative adversarial network, taking into account the texture features of the images. Subsequently, the trigger is applied to the images, and its level of stealthiness is adjusted. Compared to existing popular backdoor attack methods, the experimental results ensure a high level of stealthiness while also maintaining a high attack success rate and a high accuracy for clean data. Furthermore, our attack method exhibits considerable robustness and adaptability, demonstrating effective resistance against baseline backdoor defense techniques.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Zhang et al. (2026) studied this question.

synapsesocial.com/papers/69d896566c1944d70ce07bb6https://doi.org/10.3390/electronics15081551
Ask AI
Helpful
Bookmark
Share
View Full Paper