USENIX Security2023Top-tier venue
PELICAN: Exploiting Backdoors of Naturally Trained Deep Learning Models In Binary Code Analysis
Zhuo Zhang, Guanhong Tao, Guangyu Shen, Shengwei An, Qiuling Xu, Yingqi Liu, Yapeng Ye, Yaoxuan Wu, Xiangyu Zhang
Abstract
Deep Learning (DL) models are increasingly used in many cyber-security applications and achieve superior performance compared to traditional solutions. In this paper, we study backdoor vulnerabilities in naturally trained models used in binary analysis. These backdoors are not injected by attackers but rather products of defects in datasets and/or training processes. The attacker can exploit these vulnerabilities by injecting some small fixed input pattern (e.g., an instruction) called backdoor trigger to their input (e.g., a binary code snippet for a malware detection DL model) such that misclassification can be induced (e.g., the malware evades the detection). We focus on transformer models used in binary analysis. Given a model, we leverage a trigger inversion technique particularly designed for these models to derive trigger instructions that can induce misclassification. During attack, we utilize a novel trigger injection technique to insert the trigger instruction(s) to the input binary code snippet. The injection makes sure that the code snippets' original program semantics are preserved and the trigger becomes an integral part of such semantics and hence cannot be easily eliminated. We evaluate our prototype PELICAN on 5 binary analysis tasks and 15 models. The results show that PELICAN can effectively induce misclassification on all the evaluated models in both white-box and black-box scenarios. Our case studies demonstrate that PELICAN can exploit the backdoor vulnerabilities of two closed-source commercial tools. MOV MOV MOV [ [ [ RDX RDX RDX RDX PUSH RBP MOV RBP , RSP MOV QWORD PTR [ RBP -NUM ] , RDI MOV DWORD PTR [ RBP -NUM ] , ESI MOV RAX , QWORD PTR [ RBP -NUM ] MOV EDX , DWORD PTR [ RBP -NUM ] MOV DWORD PTR [ RAX + NUM ] , EDX POP RBP RET void f1(struct *a1, int a2, void *a3) MOV MOV MOV [ [ [ RDX RDX RDX RDX MOVSXD RAX , ESI LEA RAX , [ RAX + RAX * NUM ] SHL RAX , NUM LEA RDI , [ RDI + RAX ] LEA RSI , [ RDI + NUM ] MOV QWORD PTR [ RDI ] , RSI MOV QWORD PTR [ RSI + NUM ] , RDI MOV ESI , NUM CALL NUM RET void f2(struct *a1, int a2, void *a3) (a) Backdoored sequences of init_data (b) Backdoored sequences of init_auth_entry
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 97d912b7-d013-456c-93dd-8cef51df2c2dCited by top-tier papers5
- Django: Detecting Trojans in Object Detection Models via Gaussian Focus CalibrationGuangyu Shen, Siyuan Cheng, Guanhong Tao, Kaiyuan Zhang et al.NeurIPS 2023 · 18 citations
- Exploiting Code Symmetries for Learning Program SemanticsKexin Pei, Weichen Li, Qirui Jin, Shuyang Liu et al.ICML 2024 · 15 citations
- Binary Cryptographic Function Identification via Similarity Analysis with Path-Insensitive EmulationYikun Hu, Yituo He, Wenyu He, Haoran Li et al.OOPSLA 2025 · 2 citations
- Unlocking the Power of Differentially Private Zeroth-order Optimization for Fine-tuning LLMsErgute Bao, Yangfan Jiang, Fei Wei, Xiaokui Xiao et al.USENIX Security 2025
- Unveiling the Fragility of Binary Code Similarity Detection via Targeted Attacks with Model ExplanationsMingjie Chen, Tiancheng Zhu, Mingxue Zhang, Yiling He et al.FSE 2026
Builds on37
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Trojaning Attack on Neural NetworksYingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee et al.NDSS 2018 · 1,377 citations
- DBA: Distributed Backdoor Attacks against Federated LearningChulin Xie, Keli Huang, Pin-Yu Chen, Bo LiICLR 2020 · 901 citations
- TextBugger: Generating Adversarial Text Against Real-world ApplicationsJinfeng Li, Shouling Ji, Tianyu Du, Bo Li et al.NDSS 2019 · 876 citations
- Attack of the Tails: Yes, You Really Can Backdoor Federated LearningHongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma et al.NeurIPS 2020 · 862 citations
Related papers
- UNICORN: A Unified Backdoor Trigger Inversion FrameworkZhenting Wang, Kai Mei, Juan Zhai, Shiqing MaICLR 2023 · 7 citations
- DeepPayload: Black-box Backdoor Attack on Deep Learning Models through Neural Payload InjectionYuanchun Li, Jiayi Hua, Haoyu Wang, Chunyang Chen et al.ICSE 2021 · 70 citations
- BEAGLE: Forensics of Deep Learning Backdoor Attack for Better DefenseSiyuan Cheng, Guanhong Tao, Yingqi Liu, Shengwei An et al.NDSS 2023
- Your Compiler is Backdooring Your Model: Understanding and Exploiting Compilation Inconsistency Vulnerabilities in Deep Learning CompilersSimin Chen, Jinjun Peng, Yixin He, Junfeng Yang et al.S&P 2026 · 11 citations
- Multi-target Backdoor Attacks for Code Pre-trained ModelsYanzhou Li, Shangqing Liu, Kangjie Chen, Xiaofei Xie et al.ACL 2023 · 28 citations
