BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain

Explore this paper's citation graph

Summary

It is shown that outsourced training introduces new security risks: an adversary can create a maliciously trained network (a backdoored neural network, or a BadNet) that has state-of-the-art performance on the user's training and validation samples, but behaves badly on specific attacker-chosen inputs.

Type
preprint
Published
2017-08-22
Cited by
2,382
References
52
Access
Open access

Keywords

Backdoor, Computer science, Debugging, Classifier (UML), Traffic sign recognition

References

Cited by

Related papers