Please use this identifier to cite or link to this item: https://hdl.handle.net/10356/167428
Full metadata record
DC FieldValueLanguage
dc.contributor.authorSiew, Jun Zeen_US
dc.date.accessioned2023-05-26T08:02:19Z-
dc.date.available2023-05-26T08:02:19Z-
dc.date.issued2023-
dc.identifier.citationSiew, J. Z. (2023). Robustness of semi-supervised deep learning model against backdoor attacks. Final Year Project (FYP), Nanyang Technological University, Singapore. https://hdl.handle.net/10356/167428en_US
dc.identifier.urihttps://hdl.handle.net/10356/167428-
dc.description.abstractDeep neural networks (DNNs) have revolutionized computer vision (CV), particularly in object detection and image classification applications. However, annotating data is a costly and time-consuming process that limits the amount of labeled data available for model training. Semi-supervised learning (SSL) addresses this issue by utilizing a small portion of labeled data to learn underlying patterns and justify unlabeled data without sacrificing prediction performance. It has been demonstrated that DNNs trained by supervised learning (SL) algorithms are susceptible to data poisoning backdoor attacks. Imperceptible malicious behaviors can be embedded into activated DNNs and cause target misclassification when a specific “trigger” exists. This is due to DNNs excessive learning ability that could build a latent connection between the trigger pattern and target labels. However, the effectiveness of such backdoor attacks is rarely studied under SSL settings. Therefore, this project aims to evaluate the robustness of semi-supervised learning methods against backdoor attacks. The data-augmentation-based backdoor attack is selected in our evaluation. The attack trigger is applied separately to each image channel (R, G, B) and forms a composite trigger imperceptible to a human. This attack is conducted on a MobileNetV3 model trained on the Cifar-10 dataset using the SSL algorithm. The results show a dramatically high attack success rate of 96%, even with just a 1% injection rate of backdoored samples. This final-year project (FYP) aims to contribute to developing more secure semi-supervised learning methods that can be applied to practical applications in computer vision and methods to improve its security.en_US
dc.language.isoenen_US
dc.publisherNanyang Technological Universityen_US
dc.relationA2102-221en_US
dc.subjectEngineering::Electrical and electronic engineeringen_US
dc.titleRobustness of semi-supervised deep learning model against backdoor attacksen_US
dc.typeFinal Year Project (FYP)en_US
dc.contributor.supervisorChang Chip Hongen_US
dc.contributor.schoolSchool of Electrical and Electronic Engineeringen_US
dc.description.degreeBachelor of Engineering (Electrical and Electronic Engineering)en_US
dc.contributor.supervisoremailECHChang@ntu.edu.sgen_US
item.grantfulltextrestricted-
item.fulltextWith Fulltext-
Appears in Collections:EEE Student Reports (FYP/IA/PA/PI)
Files in This Item:
File Description SizeFormat 
FYP_SiewJunZe.pdf
  Restricted Access
Final Year Report2.39 MBAdobe PDFView/Open

Page view(s)

155
Updated on Apr 24, 2025

Download(s)

2
Updated on Apr 24, 2025

Google ScholarTM

Check

Items in DR-NTU are protected by copyright, with all rights reserved, unless otherwise indicated.