A hybrid domain-aware adaptive covert backdoor trigger generation method and system

By combining frequency and spatial domain processing to generate backdoor triggers, the problems of insufficient concealment, weak robustness, and poor adaptability in existing technologies are solved, realizing highly concealed and robust backdoor attacks, which are suitable for security vulnerability assessment and defense of deep neural networks.

CN122115228APending Publication Date: 2026-05-29UNIV OF SCI & TECH BEIJING

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
UNIV OF SCI & TECH BEIJING
Filing Date
2025-12-30
Publication Date
2026-05-29

Smart Images

  • Figure CN122115228A_ABST
    Figure CN122115228A_ABST
Patent Text Reader

Abstract

The application discloses a hybrid domain perception adaptive hidden backdoor trigger generation method and system, and relates to the technical field of artificial intelligence security. The method comprises the following steps: acquiring an original image and performing preprocessing; dividing the original image into multiple image blocks and performing frequency domain processing to generate a frequency domain disturbance image; performing spatial domain processing on the original image to generate a spatial domain texture image; combining the frequency domain disturbance image and the spatial domain texture image to generate a poisoned image containing a hidden trigger; constructing a poisoned data set, guiding a deep neural network model to perform training, and generating a poisoned model for subsequent testing. The application fully excavates image feature information in the frequency domain and the spatial domain, realizes hidden generation and adaptive embedding of the trigger, enhances the concealment and robustness of the backdoor attack, and provides an important technical reference for security evaluation of an image classification model.
Need to check novelty before this filing date? Find Prior Art