报告人:Dazhuang Liu
时间:2026年7月1日(星期三) 11:00-12:00
地点:网安大楼A12-1236
报告人简介
Dazhuang Liu is a PhD and Postdoctoral Researcher at Delft University of Technology in the Netherlands. His research centers on the security of vision neural networks and explainable machine learning, with a particular focus on backdoor attacks, adversarial examples, jailbreak attacks, and corresponding defensive mechanisms. His work has appeared at international conferences such as NDSS and GECCO, and he received the Best Paper Award in the genetic programming Track at GECCO 2022. He has also contributed to several EU Horizon research projects in machine learning and information security.
报告摘要
Current black-box backdoor attacks on convolutional neural networks typically formulate attack objectives as single-objective optimization problems in a single domain. Designing triggers in a single domain often compromises semantic consistency and trigger robustness while introducing visual and spectral anomalies. This work proposes a multi-objective black-box backdoor attack in dual domains based on an evolutionary algorithm, enabling the simultaneous optimization of multiple attack objectives without requiring prior knowledge of the victim model. In particular, the attack is formulated as a multi-objective optimization problem (MOP) and solved using a multi-objective evolutionary algorithm (MOEA). The MOEA maintains a population of candidate triggers with different trade-offs among attack objectives and employs non-dominated sorting to guide the search toward Pareto-optimal solutions. A preference-based selection strategy is further applied to eliminate impractical trigger candidates. To improve trigger stealthiness, the proposed approach minimizes the discrepancy between clean and poisoned samples in the spectral domain. In addition, robustness against common preprocessing operations is enhanced by encouraging trigger patterns to reside in low-frequency regions. Extensive experiments demonstrate that the proposed method achieves improved attack effectiveness, robustness, natural stealthiness, and spectral stealthiness.
