信息安全研究2026,Vol.12Issue(6):510-516,7.DOI:10.12379/j.issn.2096-1057.2026.06.03
基于频域注入的动态隐蔽后门攻击
Dynamic Invisible Backdoor Attack via Frequency Domain Injection
摘要
Abstract
Deep neural networks are highly vulnerable to the threat of backdoor attacks due to their non-interpretability and high dependence on data during training.Although the current mainstream backdoor attack methods generally use fixed trigger design to simplify implementation,these triggers are often significantly different from the training data distribution,resulting in easy detection and identification.To this end,this paper proposes a dynamic invisible backdoor attack method via frequency domain injection:firstly,a generative network is used to generate a specific trigger pattern based on the input samples,and then the high-frequency information of the pattern is injected into the wavelet domain of the samples,ensuring the triggers remain stealthy.Additionally,this paper designs a fair screening strategy to select samples that are more influential to the backdoor model through cosine similarity and K-means clustering algorithm.Experimental results show that this method outperforms existing methods(e.g.,BadNets,Blend,WaNet,and WABA)in terms of attack success rate and stealthiness,and effectively circumvents a variety of state-of-the-art defence mechanisms(e.g.,FP,NC,SentiNet,and SCALE-UP),providing significant robustness and extensive practical potential.关键词
后门攻击/模型安全/动态触发器/样本筛选/频域Key words
backdoor attack/model security/dynamic trigger/sample selection/frequency domain分类
信息技术与安全科学引用本文复制引用
陈先意,王晶,刘腾骏,郭倩彬,杨森..基于频域注入的动态隐蔽后门攻击[J].信息安全研究,2026,12(6):510-516,7.基金项目
国家重点研发计划项目(2021YFB2700900) (2021YFB2700900)
国家自然科学基金项目(U22B2062,62172232) (U22B2062,62172232)
江苏省杰出青年基金项目(BK20200039) (BK20200039)