The application discloses a
backdoor attack method based on color frequency injection and adaptive local enhancement, and relates to the technical field of
machine learning and
artificial intelligence security. The method comprises the following steps: introducing low-frequency color offset and weak high-frequency
signal into an image in a CIELAB
color space to perform global color-frequency injection; using a pre-trained proxy model to locate a high-sensitive
perception domain of the model through mixed evaluation of gradients and class activation maps, and generating a binary
mask; in an HSV
color space, respectively applying nonlinear stretching factors to saturation and brightness of the sensitive domain based on the
mask to perform adaptive local enhancement; using
Gaussian smoothing, adaptive
noise and
histogram matching to eliminate edges and statistical abnormalities caused by local enhancement, completing compensation
color enhancement to generate a poisoned image; and modeling a trigger core parameter as a
constrained optimization problem, and using a
particle swarm optimization algorithm to jointly dynamically update the trigger core parameter to obtain an optimal strategy. The application anchors the trigger feature depth in the core semantic area of the model and lurks in the normal data manifold, guarantees a high
attack success rate, realizes extreme visual and feature concealment, and has strong anti-defense robustness.