2020

On Certifying Robustness against Backdoor Attacks via Randomized Smoothing

Wang, Binghui, Cao, Xiaoyu, jia, Jinyuan et al.

Understand

Backdoor attack is a severe security threat to deep neural networks (DNNs).

  • We envision that, like adversarial examples, there will be a cat-and-mouse game for backdoor attacks, i.e., new empirical defenses are developed to defend against backdoor attacks but they are soon broken by strong adaptive backdoor attacks.
  • To prevent such cat-and-mouse game, we take the first step towards certified defenses against backdoor attacks.
  • Specifically, in this work, we study the feasibility and effectiveness of certifying robustness against backdoor attacks using a recent technique called randomized smoothing.

Reading the bibliography…