We present a new type of backdoor attack that exploits a vulnerability of\nconvolutional neural networks (CNNs) that has been previously unstudied. In\nparticular, we examine the application of facial recognition. Deep learning\ntechniques are at the top of the game for facial recognition, which means they\nhave now been implemented in many production-level systems. Alarmingly, unlike\nother commercial technologies such as operating systems and network devices,\ndeep learning-based facial recognition algorithms are not presently designed\nwith security requirements or audited for security vulnerabilities before\ndeployment. Given how young the technology is and how abstract many of the\ninternal workings of these algorithms are, neural network-based facial\nrecognition systems are prime targets for security breaches. As more and more\nof our personal information begins to be guarded by facial recognition (e.g.,\nthe iPhone X), exploring the security vulnerabilities of these systems from a\npenetration testing standpoint is crucial. Along these lines, we describe a\ngeneral methodology for backdooring CNNs via targeted weight perturbations.\nUsing a five-layer CNN and ResNet-50 as case studies, we show that an attacker\nis able to significantly increase the chance that inputs they supply will be\nfalsely accepted by a CNN while simultaneously preserving the error rates for\nlegitimate enrolled classes.\n
Paper
References (33)
Scroll for more · 21 remaining