PELICAN: Exploiting Backdoors of Naturally Trained Deep Learning Models In Binary Code Analysis
Zhuo Zhang, Guanhong Tao, Guangyu Shen, Shengwei An, Qiuling Xu, Yingqi Liu, Yapeng Ye, Yaoxuan Wu, Xiangyu Zhang
摘要
Deep Learning (DL) models are increasingly used in many cyber-security applications and achieve superior performance compared to traditional solutions. In this paper, we study backdoor vulnerabilities in naturally trained models used in binary analysis. These backdoors are not injected by attackers but rather products of defects in datasets and/or training processes. The attacker can exploit these vulnerabilities by injecting some small fixed input pattern (e.g., an instruction) called backdoor trigger to their input (e.g., a binary code snippet for a malware detection DL model) such that misclassification can be induced (e.g., the malware evades the detection). We focus on transformer models used in binary analysis. Given a model, we leverage a trigger inversion technique particularly designed for these models to derive trigger instructions that can induce misclassification. During attack, we utilize a novel trigger injection technique to insert the trigger instruction(s) to the input binary code snippet. The injection makes sure that the code snippets' original program semantics are preserved and the trigger becomes an integral part of such semantics and hence cannot be easily eliminated. We evaluate our prototype PELICAN on 5 binary analysis tasks and 15 models. The results show that PELICAN can effectively induce misclassification on all the evaluated models in both white-box and black-box scenarios. Our case studies demonstrate that PELICAN can exploit the backdoor vulnerabilities of two closed-source commercial tools. MOV MOV MOV [ [ [ RDX RDX RDX RDX PUSH RBP MOV RBP , RSP MOV QWORD PTR [ RBP -NUM ] , RDI MOV DWORD PTR [ RBP -NUM ] , ESI MOV RAX , QWORD PTR [ RBP -NUM ] MOV EDX , DWORD PTR [ RBP -NUM ] MOV DWORD PTR [ RAX + NUM ] , EDX POP RBP RET void f1(struct *a1, int a2, void *a3) MOV MOV MOV [ [ [ RDX RDX RDX RDX MOVSXD RAX , ESI LEA RAX , [ RAX + RAX * NUM ] SHL RAX , NUM LEA RDI , [ RDI + RAX ] LEA RSI , [ RDI + NUM ] MOV QWORD PTR [ RDI ] , RSI MOV QWORD PTR [ RSI + NUM ] , RDI MOV ESI , NUM CALL NUM RET void f2(struct *a1, int a2, void *a3) (a) Backdoored sequences of init_data (b) Backdoored sequences of init_auth_entry
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Django: Detecting Trojans in Object Detection Models via Gaussian Focus CalibrationGuangyu Shen, Siyuan Cheng, Guanhong Tao, Kaiyuan Zhang 等NeurIPS 2023 · 被引用 18 次
- Exploiting Code Symmetries for Learning Program SemanticsKexin Pei, Weichen Li, Qirui Jin, Shuyang Liu 等ICML 2024 · 被引用 15 次
- Binary Cryptographic Function Identification via Similarity Analysis with Path-Insensitive EmulationYikun Hu, Yituo He, Wenyu He, Haoran Li 等OOPSLA 2025 · 被引用 2 次
- Unlocking the Power of Differentially Private Zeroth-order Optimization for Fine-tuning LLMsErgute Bao, Yangfan Jiang, Fei Wei, Xiaokui Xiao 等USENIX Security 2025
- Unveiling the Fragility of Binary Code Similarity Detection via Targeted Attacks with Model ExplanationsMingjie Chen, Tiancheng Zhu, Mingxue Zhang, Yiling He 等FSE 2026
它引用的顶会 Paper37
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Trojaning Attack on Neural NetworksYingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee 等NDSS 2018 · 被引用 1,377 次
- DBA: Distributed Backdoor Attacks against Federated LearningChulin Xie, Keli Huang, Pin-Yu Chen, Bo LiICLR 2020 · 被引用 901 次
- TextBugger: Generating Adversarial Text Against Real-world ApplicationsJinfeng Li, Shouling Ji, Tianyu Du, Bo Li 等NDSS 2019 · 被引用 876 次
- Attack of the Tails: Yes, You Really Can Backdoor Federated LearningHongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma 等NeurIPS 2020 · 被引用 862 次
相关 Paper
- UNICORN: A Unified Backdoor Trigger Inversion FrameworkZhenting Wang, Kai Mei, Juan Zhai, Shiqing MaICLR 2023 · 被引用 7 次
- DeepPayload: Black-box Backdoor Attack on Deep Learning Models through Neural Payload InjectionYuanchun Li, Jiayi Hua, Haoyu Wang, Chunyang Chen 等ICSE 2021 · 被引用 70 次
- BEAGLE: Forensics of Deep Learning Backdoor Attack for Better DefenseSiyuan Cheng, Guanhong Tao, Yingqi Liu, Shengwei An 等NDSS 2023
- Your Compiler is Backdooring Your Model: Understanding and Exploiting Compilation Inconsistency Vulnerabilities in Deep Learning CompilersSimin Chen, Jinjun Peng, Yixin He, Junfeng Yang 等S&P 2026 · 被引用 11 次
- Multi-target Backdoor Attacks for Code Pre-trained ModelsYanzhou Li, Shangqing Liu, Kangjie Chen, Xiaofei Xie 等ACL 2023 · 被引用 28 次
