Our new X account is live! Follow @wizwand_team for updates
WorkDL logo mark

UOR: Universal Backdoor Attacks on Pre-trained Language Models

About

Backdoors implanted in pre-trained language models (PLMs) can be transferred to various downstream tasks, which exposes a severe security threat. However, most existing backdoor attacks against PLMs are un-targeted and task-specific. Few targeted and task-agnostic methods use manually pre-defined triggers and output representations, which prevent the attacks from being more effective and general. In this paper, we first summarize the requirements that a more threatening backdoor attack against PLMs should satisfy, and then propose a new backdoor attack method called UOR, which breaks the bottleneck of the previous approach by turning manual selection into automatic optimization. Specifically, we define poisoned supervised contrastive learning which can automatically learn the more uniform and universal output representations of triggers for various PLMs. Moreover, we use gradient search to select appropriate trigger words which can be adaptive to different PLMs and vocabularies. Experiments show that our method can achieve better attack performance on various text classification tasks compared to manual methods. Further, we tested our method on PLMs with different architectures, different usage paradigms, and more difficult tasks, which demonstrated the universality of our method.

Wei Du, Peixuan Li, Boqun Li, Haodong Zhao, Gongshen Liu• 2023

Related benchmarks

TaskDatasetResultRank
Text Classification11 text classification tasks
Average Performance60.57
34
Named Entity RecognitionCoNLL (test)--
28
Spam DetectionLingspam
CACC99.14
10
Binary ClassificationSST-2
Accuracy92.89
6
Binary ClassificationENRON
ACC99.05
6
Binary ClassificationHateSpeech
Accuracy92.5
6
Multi-ClassificationAGNews
Accuracy94.49
6
Multi-ClassificationYelp
ACC99.16
6
Binary ClassificationIMDB
Accuracy93.2
6
Binary ClassificationTwitter
ACC94.52
6
Showing 10 of 14 rows

Other info

Follow for update