Lune

INFOCOM2026顶会

TrojanEdge: Mutual Information-Enhanced Robust and Persistent Backdoor Attacks for Edge and On-Device Deployments

Zemin Chen, Jian Li, Miao Lin, Austin Mao, Lusi Li, Rui Ning, Chunsheng Xin, Hongyi Wu

2026年份

摘要

Backdoor attacks pose a significant security threat to deep neural networks (DNNS) by implanting hidden malicious behaviors triggered by specific input patterns. While these attacks typically retain high clean accuracy, their effectiveness can be severely diminished through post-deployment adaptations including fine-tuning, model pruning and quantization techniques commonly applied in edge environments, especially using imbalanced local data. Such scenarios frequently occur in practice due to limited user data, natural distribution skews in downstream tasks, and resource constraints requiring model compression. Existing backdoor injection methods generally overlook these challenges, leaving them vulnerable to suppression during real-world model adaptation. To address this critical limitation, we propose TrojanEdge, a mutual information-enhanced training framework designed for robust and persistent backdoor attacks. TrojanEdge explicitly maximizes mutual information between gradients derived from poisoned data and class-imbalanced data while incorporating dropout-based regularization to enhance robustness against parameter perturbations from pruning and quantization, effectively mitigating gradient drift and structural modifications during post-deployment optimizations. Experiments conducted on MNIST, ,CIFAR-10, and ImageNet-10 demonstrate that TrojanEdge consistently achieves high attack success rates (ASR ≥ 96%) after balanced and imbalanced fine-tuning, pruning, and quantization scenarios, while maintaining competitive clean accuracy.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖