Your Compiler is Backdooring Your Model: Understanding and Exploiting Compilation Inconsistency Vulnerabilities in Deep Learning Compilers
Simin Chen, Jinjun Peng, Yixin He, Junfeng Yang, Baishakhi Ray
摘要
Deep learning (DL) compilers serve as essential infrastructure in modern DL systems. In this work, we uncover a fundamental security vulnerability inherent in the design principles of DL compilers. Specifically, we ask: Can an official, unmodified DL compiler change a DL model's semantics during compilation, and can such changes introduce hidden backdoors? To answer this question, we consider both adversarial and natural in-the-wild settings. In the adversarial setting, we propose an attack that generates a benign DL model where the backdoor trigger has no effect on the model's behavior. However, after compilation, this benign model is transformed into a backdoored version, allowing the trigger to influence its decisions successfully. We evaluate our approach on six DL models, three commercial compilers, and two hardware platforms. Pre-compilation models show no trigger effects and remain undetected by four state-of-the-art backdoor detectors. In contrast, post-compilation models achieve a 100 % attack success rate on triggered inputs while preserving normal behavior on clean inputs, with a prediction consistency rate with the pre-compilation model. Our attack generalizes across different compiler-hardware combinations and floating-point settings. Beyond the intentional adversarial setting, we further conduct an in-the-wild analysis of the top most-downloaded models on HuggingFace-including one with over 220 million downloads-and uncover natural triggers in 31 models using a gradient-guided method. These findings suggest that DL compilers may unintentionally introduce security risks, even in the absence of explicit attacks. Our results uncover an overlooked threat in the ML stack: unmodified DL compilers can silently change the model semantics during compilation. To our knowledge, our work is the first work to demonstrate the inherent security risks of DL compiler design, highlighting a new frontier for secure and trustworthy machine learning11.Our project page and code are available at the following link..
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- IAG: Input-aware Backdoor Attack on VLM-based Visual GroundingJunxian Li, Beining Xu, Simin Chen, Jiatong Li 等CVPR 2026 · 被引用 13 次
- (A)iSpy: Parasitic Trojans for Machine Learning InfrastructureHabibur Rahaman, Qipan Xu, Zafaryab Haider, Prabuddha Chakraborty 等CCS 2026
它引用的顶会 Paper39
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li 等S&P 2019 · 被引用 1,801 次
- Trojaning Attack on Neural NetworksYingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee 等NDSS 2018 · 被引用 1,377 次
- Input-Aware Dynamic Backdoor AttackTuan Anh Nguyen, Anh Tuan TranNeurIPS 2020 · 被引用 601 次
- Ansor: Generating High-Performance Tensor Programs for Deep LearningLianmin Zheng, Chengfan Jia, Minmin Sun, Zhao Wu 等OSDI 2020 · 被引用 551 次
- Demon in the Variant: Statistical Analysis of DNNs for Robust Backdoor Contamination DetectionDi Tang, XiaoFeng Wang, Haixu Tang, Kehuan ZhangUSENIX Security 2021 · 被引用 242 次
相关 Paper
- DeepPayload: Black-box Backdoor Attack on Deep Learning Models through Neural Payload InjectionYuanchun Li, Jiayi Hua, Haoyu Wang, Chunyang Chen 等ICSE 2021 · 被引用 70 次
- PELICAN: Exploiting Backdoors of Naturally Trained Deep Learning Models In Binary Code AnalysisZhuo Zhang, Guanhong Tao, Guangyu Shen, Shengwei An 等USENIX Security 2023
- A comprehensive study of deep learning compiler bugsQingchao Shen, Haoyang Ma, Junjie Chen, Yongqiang Tian 等FSE 2021 · 被引用 123 次
- DeBackdoor: A Deductive Framework for Detecting Backdoor Attacks on Deep Models with Limited DataDorde Popovic, Amin Sadeghi, Ting Yu, Sanjay Chawla 等USENIX Security 2025
- Demystifying Poisoning Backdoor Attacks from a Statistical PerspectiveGanghua Wang, Xun Xian, Ashish Kundu, Jayanth Srinivasa 等ICLR 2024 · 被引用 11 次
