In this talk I will describe how to plant novel types of backdoors in any facial recognition model based on the popular architecture of deep Siamese neural networks, by mathematically changing a small fraction of its weights (i.e., without using any additional training or optimization). These backdoors force the system to err only on specific persons which are preselected by the attacker. For example, we show how such a backdoored system can take any two images of a particular person and decide that they represent different persons (an anonymity attack), or take any two images of a particular pair of persons and decide that they represent the same person (a confusion attack), with almost no effect on the correctness of its decisions for other persons. Uniquely, we show that multiple backdoors can be independently installed by multiple attackers who may not be aware of each other's existence with almost no interference.
Joint work with Irad Zehavi.
嘉宾介绍
Adi Shamir
图灵奖获得者John Hopcroft
图灵奖获得者、美国国家科学院院士、美国国家工程院院士、中国科学院外籍院士姚期智
图灵奖获得者、中国科学院院士活动议程
-
2023-07-12 15:30:00~17:00:00
议程描述:炉边对话:人工智能时代创新教育的“密码”
议程详情:主持人:徐学敏 对话嘉宾:Adi Shamir、John Hopcroft、姚期智
-
2023-07-12 14:00:00~15:30:00
议程描述:大师讲坛:Facial Misrecognition Systems
议程详情:主讲人:Adi Shamir