Model Pirating and Backdoor Injection Attacks in Data-Free Setting
Document Type
Conference Proceeding
Publication Date
1-1-2026
Abstract
It has been demonstrated that DNN models are vulnerable to backdoor attacks, in which an attacker can inject a backdoor into a DNN model such that it predicts any input with an attacker-specific backdoor trigger as the target label. However, most prior attacks require original or substitute datasets, limiting their applicability when these datasets are unavailable. In this paper, we propose model pirating and backdoor injecting (MPBI) attacks in the data-free setting, enabling an attacker to inject backdoors into pirated DNNs without requiring any training data. MPBI attack employs the GAN-inspired generation method to synthesize samples aligned with the original training data distribution of the target model and then adapts knowledge distillation principles to transfer functionality to the pirated model while embedding a hidden backdoor into it. MPBI offers three advantages: complete data independence, support for arbitrary triggers, and compatibility with heterogeneous model architectures. Extensive experiments on MNIST, Fashion-MNIST, and CIFAR-10 demonstrate high attack success rates with minimal accuracy degradation.
Publication Title
Proceedings of the International Conference on Computer Supported Cooperative Work in Design Cscwd
Recommended Citation
Hu, A.,
Lei, X.,
Chen, X.,
&
Zhou, X.
(2026).
Model Pirating and Backdoor Injection Attacks in Data-Free Setting.
Proceedings of the International Conference on Computer Supported Cooperative Work in Design Cscwd(2026), 1859-1864.
http://doi.org/10.1109/CSCWD68734.2026.11582391
Retrieved from: https://digitalcommons.mtu.edu/michigantech-p2/2841