Multi-Objective Backdoor Attack via Evolutionary Algorithm

发布时间:2026-06-29

作者:

报告人:Dazhuang Liu

时间:2026年7月1日(星期三) 11:00-12:00

地点:网安大楼A12-1236

报告人简介

Dazhuang Liu is a PhD and Postdoctoral Researcher at Delft University of Technology in the Netherlands. His research centers on the security of vision neural networks and explainable machine learning, with a particular focus on backdoor attacks, adversarial examples, jailbreak attacks, and corresponding defensive mechanisms. His work has appeared at international conferences such as NDSS and GECCO, and he received the Best Paper Award in the genetic programming Track at GECCO 2022. He has also contributed to several EU Horizon research projects in machine learning and information security.

报告摘要

Current black-box backdoor attacks on convolutional neural networks typically formulate attack objectives as single-objective optimization problems in a single domain. Designing triggers in a single domain often compromises semantic consistency and trigger robustness while introducing visual and spectral anomalies. This work proposes a multi-objective black-box backdoor attack in dual domains based on an evolutionary algorithm, enabling the simultaneous optimization of multiple attack objectives without requiring prior knowledge of the victim model. In particular, the attack is formulated as a multi-objective optimization problem (MOP) and solved using a multi-objective evolutionary algorithm (MOEA). The MOEA maintains a population of candidate triggers with different trade-offs among attack objectives and employs non-dominated sorting to guide the search toward Pareto-optimal solutions. A preference-based selection strategy is further applied to eliminate impractical trigger candidates. To improve trigger stealthiness, the proposed approach minimizes the discrepancy between clean and poisoned samples in the spectral domain. In addition, robustness against common preprocessing operations is enhanced by encouraging trigger patterns to reside in low-frequency regions. Extensive experiments demonstrate that the proposed method achieves improved attack effectiveness, robustness, natural stealthiness, and spectral stealthiness.

联系我们

南校区地址:陕西省西安市西沣路兴隆段266号邮编:710126

北校区地址:陕西省西安市太白南路2号邮编:710071

电话:029-88201000

学校官微

研究院官微

版权所有:数学与交叉科学研究院    建设与运维:信息网络技术中心     西安聚力

陕ICP备05016463号    陕公网安备61019002002681号