Rethinking the Stealthiness of Cryptographically Undetectable Backdoors in Practical RFF Learning
Tianshuo Cong, Pei Li, Haojie Wu, Jinyuan Liu, Tairong Huang, Guoyan Zhang, Anyu Wang
摘要
Random Fourier Features (RFF) learning is a classical technique in scalable data mining. However, at FOCS 2022, Goldwasser et al. proposed a theoretical framework for planting cryptographically undetectable backdoors in RFF learning based on the hardness of the Continuous Learning With Errors (CLWE) problem. Their construction guarantees white-box undetectability in the model parameter space against any polynomial-time distinguisher. In this paper, we revisit the undetectability of CLWE backdoors from a practical RFF learning perspective. We prove that the operational validity of the CLWE backdoor critically hinges on assumptions that are incompatible with the realistic RFF learning deployment. Specifically, standard data preprocessing required for effective RFF learning fundamentally destroys the input-space stealthiness of CLWE backdoors, inevitably resulting in conspicuous input-level artifacts. We further validate our theoretical findings through extensive experiments on both tabular and image datasets, demonstrating that simple sanity checks at the input level suffice to reliably identify backdoored inputs. In addition, under the same threat model, we analyze the adversarial robustness of RFF learning models and provide a concrete certified robustness analysis, enabling a deeper security assessment of its practical deployment. Overall, our work emphasizes the importance of evaluating theoretical backdoor attacks under realistic machine learning pipelines and offers broader insights into the secure deployment of RFF learning systems.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Planting Undetectable Backdoors in Machine Learning Models : [Extended Abstract]Shafi Goldwasser, Michael P. Kim, Vinod Vaikuntanathan, Or ZamirFOCS 2022 · 被引用 40 次
- Oblivious Defense in ML Models: Backdoor Removal without DetectionShafi Goldwasser, Jonathan Shafer, Neekon Vafa, Vinod VaikuntanathanSTOC 2025 · 被引用 4 次
- Injecting Undetectable Backdoors in Obfuscated Neural Networks and Language ModelsAlkis Kalavasis, Amin Karbasi, Argyris Oikonomou, Katerina Sotiraki 等NeurIPS 2024 · 被引用 5 次
- Machine Learning needs Better Randomness Standards: Randomised Smoothing and PRNG-based attacksPranav Dahiya, Ilia Shumailov, Ross AndersonUSENIX Security 2024 · 被引用 11 次
- ReVeil: Unconstrained Concealed Backdoor Attack on Deep Neural Networks using Machine UnlearningManaar Alam, Hithem Lamri, Michail ManiatakosDAC 2025 · 被引用 3 次
