Source author record

Shaofeng Li

Shaofeng Li appears in the imported research catalog. Authorship, coauthor and topic links are available while profile ownership is still unclaimed.

ResearcherUnclaimed source record

Catalog footprint

What is connected

4works
5topics
4close collaborators

Actions

Connect this record

Log in to claim

Research graph

See the researcher in context

Open full explorer

Inspect adjacent papers, topics, institutions and collaborators without losing the researcher page.

Building this map preview

BZPEER is loading the nearby papers, people, topics and institutions for this page.

Published work

4 published item(s)

preprint2022arXiv

Fingerprinting Deep Neural Networks Globally via Universal Adversarial Perturbations

In this paper, we propose a novel and practical mechanism which enables the service provider to verify whether a suspect model is stolen from the victim model via model extraction attacks. Our key insight is that the profile of a DNN model's decision boundary can be uniquely characterized by its Universal Adversarial Perturbations (UAPs). UAPs belong to a low-dimensional subspace and piracy models' subspaces are more consistent with victim model's subspace compared with non-piracy model. Based on this, we propose a UAP fingerprinting method for DNN models and train an encoder via contrastive learning that takes fingerprint as inputs, outputs a similarity score. Extensive studies show that our framework can detect model IP breaches with confidence > 99.99 within only 20 fingerprints of the suspect model. It has good generalizability across different model architectures and is robust against post-modifications on stolen models.

preprint2021arXiv

Deep Learning Backdoors

Intuitively, a backdoor attack against Deep Neural Networks (DNNs) is to inject hidden malicious behaviors into DNNs such that the backdoor model behaves legitimately for benign inputs, yet invokes a predefined malicious behavior when its input contains a malicious trigger. The trigger can take a plethora of forms, including a special object present in the image (e.g., a yellow pad), a shape filled with custom textures (e.g., logos with particular colors) or even image-wide stylizations with special filters (e.g., images altered by Nashville or Gotham filters). These filters can be applied to the original image by replacing or perturbing a set of image pixels.

preprint2020arXiv

Invisible Backdoor Attacks on Deep Neural Networks via Steganography and Regularization

Deep neural networks (DNNs) have been proven vulnerable to backdoor attacks, where hidden features (patterns) trained to a normal model, which is only activated by some specific input (called triggers), trick the model into producing unexpected behavior. In this paper, we create covert and scattered triggers for backdoor attacks, invisible backdoors, where triggers can fool both DNN models and human inspection. We apply our invisible backdoors through two state-of-the-art methods of embedding triggers for backdoor attacks. The first approach on Badnets embeds the trigger into DNNs through steganography. The second approach of a trojan attack uses two types of additional regularization terms to generate the triggers with irregular shape and size. We use the Attack Success Rate and Functionality to measure the performance of our attacks. We introduce two novel definitions of invisibility for human perception; one is conceptualized by the Perceptual Adversarial Similarity Score (PASS) and the other is Learned Perceptual Image Patch Similarity (LPIPS). We show that the proposed invisible backdoors can be fairly effective across various DNN models as well as four datasets MNIST, CIFAR-10, CIFAR-100, and GTSRB, by measuring their attack success rates for the adversary, functionality for the normal users, and invisibility scores for the administrators. We finally argue that the proposed invisible backdoor attacks can effectively thwart the state-of-the-art trojan backdoor detection approaches, such as Neural Cleanse and TABOR.

preprint2015arXiv

Higgs boson production and decay at $e^{+}e^{-}$ colliders as a probe of the Left-Right twin Higgs model

In the framework of the Left-Right twin Higgs (LRTH) model, we consider the constrains from the latest search for high-mass dilepton resonances at the LHC and find that the heavy neutral boson $Z_H$ is excluded with mass below 2.76 TeV. Under these constrains, we study the Higgs-Gauge coupling production processes $e^{+}e^{-}\rightarrow ZH$, $e^{+}e^{-}\rightarrow ν_{e}\bar{ν_{e}}H$ and $e^{+}e^{-}\rightarrow e^{+}e^{-}H$, top quark Yukawa coupling production process $e^{+}e^{-}\rightarrow t\bar{t}H$, Higgs self-couplings production processes $e^{+}e^{-}\rightarrow ZHH$ and $e^{+}e^{-}\rightarrow ν_{e}\bar{ν_{e}}HH$ at $e^{+}e^{-}$ colliders. Besides, we study the major decay modes of the Higgs boson, namely $h\rightarrow f\bar{f}$($f=b,c,τ$), $VV^{*}(V=W, Z)$, $gg$, $γγ$. We find that the LRTH effects are sizable so that the Higgs boson processes at $e^{+}e^{-}$ collider can be a sensitive probe for the LRTH model.