Adaptive EWC Method Enhances Stealthy Text-to-Image Backdoor Attacks
Researchers have introduced a novel technique called Cosine-Aware Adaptive Elastic Weight Consolidation (EWC) to improve the effectiveness of backdoor attacks in text-to-image (T2I) generative models. Published on arXiv, the study addresses the limitations of existing methods like Learning without Forgetting (LwF), which often struggle to balance attack success rates with model fidelity. The authors demonstrate that standard static EWC creates an artificial trade-off, particularly weakening performance on subtle triggers. Their proposed adaptive approach dynamically adjusts regularization using cosine-based semantic utility and adaptive scheduling. This transforms EWC from a fixed penalty into a context-sensitive constraint, allowing attackers to maintain high success rates while preserving the visual quality and functionality of the compromised model. Experimental results indicate that this method offers a superior balance between attack efficacy and stealth, along with enhanced robustness on out-of-domain datasets compared to current baselines. This development highlights evolving security vulnerabilities in AI generative systems, suggesting that parameter-based regularization can be exploited to create more persistent and undetectable malicious modifications in machine learning models.
Wire timeline
Adaptive EWC Method Enhances Stealthy Text-to-Image Backdoor Attacks
Researchers have introduced a novel technique called Cosine-Aware Adaptive Elastic Weight Consolidation (EWC) to improve the effectiveness of backdoor attacks in text-to-image (T2I) generative models. Published on arXiv, the study addresses the limitations of existing methods like Learning without Forgetting (LwF), which often struggle to balance attack success rates with model fidelity. The authors demonstrate that standard static EWC creates an artificial trade-off, particularly weakening performance on subtle triggers. Their proposed adaptive approach dynamically adjusts regularization using cosine-based semantic utility and adaptive scheduling. This transforms EWC from a fixed penalty into a context-sensitive constraint, allowing attackers to maintain high success rates while preserving the visual quality and functionality of the compromised model. Experimental results indicate that this method offers a superior balance between attack efficacy and stealth, along with enhanced robustness on out-of-domain datasets compared to current baselines. This development highlights evolving security vulnerabilities in AI generative systems, suggesting that parameter-based regularization can be exploited to create more persistent and undetectable malicious modifications in machine learning models.
cs.AI updates on arXiv.org