{"id":"https://openalex.org/W4312122256","doi":"https://doi.org/10.48550/arxiv.2212.11751","title":"Mind Your Heart: Stealthy Backdoor Attack on Dynamic Deep Neural Network in Edge Computing","display_name":"Mind Your Heart: Stealthy Backdoor Attack on Dynamic Deep Neural Network in Edge Computing","publication_year":2022,"publication_date":"2022-01-01","ids":{"openalex":"https://openalex.org/W4312122256","doi":"https://doi.org/10.48550/arxiv.2212.11751"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2212.11751","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},"type":"preprint","type_crossref":"posted-content","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/abs/2212.11751","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5102779554","display_name":"Tian Dong","orcid":"https://orcid.org/0000-0002-6343-4207"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Dong, Tian","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100730159","display_name":"Ziyuan Zhang","orcid":"https://orcid.org/0000-0002-4547-5283"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Ziyuan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101533633","display_name":"Han Qiu","orcid":"https://orcid.org/0000-0002-1470-0978"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Qiu, Han","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101591101","display_name":"Tianwei Zhang","orcid":"https://orcid.org/0000-0001-6595-6650"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Tianwei","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5011803365","display_name":"Hewu Li","orcid":"https://orcid.org/0000-0002-6331-6542"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Hewu","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5029034178","display_name":"Terry Wang","orcid":"https://orcid.org/0000-0002-9852-0025"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Terry","raw_affiliation_strings":[],"affiliations":[]}],"institution_assertions":[],"countries_distinct_count":0,"institutions_distinct_count":0,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.0,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":0,"max":60},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9903,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9883,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9982079},{"id":"https://openalex.org/keywords/edge-device","display_name":"Edge device","score":0.48890677}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9982079},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7877689},{"id":"https://openalex.org/C162307627","wikidata":"https://www.wikidata.org/wiki/Q204833","display_name":"Enhanced Data Rates for GSM Evolution","level":2,"score":0.53926164},{"id":"https://openalex.org/C174333608","wikidata":"https://www.wikidata.org/wiki/Q19635","display_name":"Trojan","level":2,"score":0.49459884},{"id":"https://openalex.org/C138236772","wikidata":"https://www.wikidata.org/wiki/Q25098575","display_name":"Edge device","level":3,"score":0.48890677},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.47765768},{"id":"https://openalex.org/C2778456923","wikidata":"https://www.wikidata.org/wiki/Q5337692","display_name":"Edge computing","level":3,"score":0.47117},{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.45325145},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.45227605},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.43509197},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4070116},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.40654305},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.25491887},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.13673207}],"mesh":[],"locations_count":3,"locations":[{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2212.11751","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"http://arxiv.org/abs/2212.11751","pdf_url":"http://arxiv.org/pdf/2212.11751","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":false,"landing_page_url":"https://api.datacite.org/dois/10.48550/arxiv.2212.11751","pdf_url":null,"source":{"id":"https://openalex.org/S4393179698","display_name":"DataCite API","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4210145204","host_organization_name":"DataCite","host_organization_lineage":["https://openalex.org/I4210145204"],"host_organization_lineage_names":["DataCite"],"type":"metadata"},"license":null,"license_id":null,"version":null}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2212.11751","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},"sustainable_development_goals":[],"grants":[],"datasets":[],"versions":[],"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4392003106","https://openalex.org/W4389518867","https://openalex.org/W4387929148","https://openalex.org/W4316804661","https://openalex.org/W4308244459","https://openalex.org/W4226092343","https://openalex.org/W4221166349","https://openalex.org/W4200628936","https://openalex.org/W3106646114","https://openalex.org/W2969023901"],"abstract_inverted_index":{"Transforming":[0],"off-the-shelf":[1],"deep":[2],"neural":[3],"network":[4],"(DNN)":[5],"models":[6],"into":[7,109],"dynamic":[8,47,111],"multi-exit":[9,48,75,112],"architectures":[10],"can":[11],"achieve":[12],"inference":[13],"and":[14,19,32,85,106,133,141,143],"transmission":[15],"efficiency":[16],"by":[17,56],"fragmenting":[18],"distributing":[20],"a":[21,40,54,110],"large":[22],"DNN":[23,49,59,68],"model":[24,69,80,105],"in":[25],"edge":[26,30],"computing":[27],"scenarios":[28],"(e.g.,":[29],"devices":[31],"cloud":[33],"servers).":[34],"In":[35],"this":[36,66,104],"paper,":[37],"we":[38,52],"propose":[39],"novel":[41],"backdoor":[42,55,96,145,152],"attack":[43,127],"specifically":[44],"on":[45,83,128],"the":[46,91,95,101,123],"models.":[50],"Particularly,":[51],"inject":[53],"poisoning":[57],"one":[58],"model's":[60],"shallow":[61],"hidden":[62],"layers":[63],"targeting":[64],"not":[65],"vanilla":[67,79],"but":[70],"only":[71],"its":[72],"dynamically":[73],"deployed":[74],"architectures.":[76],"Our":[77],"backdoored":[78],"behaves":[81],"normally":[82],"performance":[84],"cannot":[86],"be":[87,98],"activated":[88,99],"even":[89],"with":[90,135],"correct":[92],"trigger.":[93],"However,":[94],"will":[97],"when":[100],"victims":[102],"acquire":[103],"transform":[107],"it":[108],"architecture":[113],"at":[114],"their":[115],"deployment.":[116],"We":[117],"conduct":[118],"extensive":[119],"experiments":[120],"to":[121,148],"prove":[122],"effectiveness":[124],"of":[125],"our":[126,144],"three":[129],"structures":[130],"(ResNet-56,":[131],"VGG-16,":[132],"MobileNet)":[134],"four":[136],"datasets":[137],"(CIFAR-10,":[138],"SVHN,":[139],"GTSRB,":[140],"Tiny-ImageNet)":[142],"is":[146],"stealthy":[147],"evade":[149],"multiple":[150],"state-of-the-art":[151],"detection":[153],"or":[154],"removal":[155],"methods.":[156]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4312122256","counts_by_year":[],"updated_date":"2024-12-12T17:13:41.746803","created_date":"2023-01-04"}