[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-119614-en":3,"doc-seo-119614-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},119614,1099514068365,"Aurelia","https://ap-avatar.wpscdn.com/avatar/10000253d8d9f28188e?_k=1776742907772140068",8,"Research & Report","Backdoors on Manifold Learning - Research and Experiment Findings","Backdoors on Manifold Learning investigates whether backdoor attacks remain effective after applying manifold learning to poisoned data. The study examines two manifold learning techniques, Autoencoder and UMAP, over two benchmark datasets, MNIST and CIFAR10, under two backdoor strategies: clean label and dirty label. Extensive experiments across varying parameters show attack success rates up to 95% for Autoencoder and 75% for UMAP even after reducing data to two dimensions.","Backdoors on Manifold Learning  \nChristina Kreza  \nRadboud University Nijmegen, the Netherlands [krezacr@gmail.com](krezacr@gmail.com)  \nStefanos Koffas  \nDelft University of Technology Delft, the Netherlands [s.koffas@tudelft.nl](s.koffas@tudelft.nl)  \nBehrad Tajalli  \nRadboud University Nijmegen, the Netherlands [hamidreza.tajalli@ru.nl](hamidreza.tajalli@ru.nl)  \nMauro Conti  \nUniversity of Padua Padua, Italy [mauro.conti@unipd.it](mauro.conti@unipd.it)  \nStjepan Picek  \nRadboud University Nijmegen, the Netherlands Delft University of Technology Delft, the Netherlands [stjepan.picek@ru.nl](stjepan.picek@ru.nl)  \nABSTRACT  \nRecently, attackers have targeted machine learning systems, introducing various attacks. The backdoor attack is popular in this field and is usually realized through data poisoning. To the best of our knowledge, we are the first to investigate whether the backdoor attacks remain effective when manifold learning algorithms are applied to the poisoned dataset. We conducted our experiments using two manifold learning techniques (Autoencoder and UMAP) on two benchmark datasets (MNIST and CIFAR10) and two backdoor strategies (clean and dirty label) . We performed an array of experiments using different parameters, finding that we could reach an attack success rate of 95% and 75% even after reducing our data to two dimensions using Autoencoders and UMAP, respectively.  \nCCS CONCEPTS  \n• Computing methodologies → Neural networks; • Security and privacy → Systems security.  \nKEYWORDS  \nManifold Learning, Backdoor Attacks, UMAP, Autoencoders  \nACM Reference Format:  \nChristina Kreza, Stefanos Koffas, Behrad Tajalli, Mauro Conti, and Stjepan Picek. 2024. Backdoors on Manifold Learning. In Proceedings of the 2024 ACM Workshop on Wireless Security and Machine Learning (WiseML’24), May 31, 2024, Seoul, Republic of Korea. ACM, New York, NY, USA, 7 pages. [https://doi.org/10.1145/3649403.3656484](https://doi.org/10.1145/3649403.3656484)  \n1 INTRODUCTION  \nDeep learning’s increased popularity in recent years and its application to various domains led to the introduction of adversarial machine learning. Adversarial machine learning compromises machine learning systems, targeting their integrity, availability, or confidentiality [10]. The backdoor attack [7] is a popular attack in this field, usually done through data poisoning, which was made  \nThis work is licensed under a Creative Commons Attribution International 4 .0 License.  \nWiseML’24, May 31, 2024, Seoul, Republic of Korea © 2024 Copyright held by the owner/author(s) . ACM ISBN 979-8-4007-0602-8/24/05 . [https://doi.org/10.1145/3649403.3656484](https://doi.org/10.1145/3649403.3656484)  \npossible through crowdsourced datasets like Imagenet [6] or machine learning as a service [7] . For this attack, the attacker inserts a secret functionality into the model that is activated during inference by malicious inputs with a specific property (trigger) .  \nManifold learning is connected to the problem of (non-linear) dimensionality reduction. Manifold learning can be used in applications where high-dimensional data like images (each pixel can be considered as a feature) are represented as lower-dimensional data (not all pixels are equally important or there is a high correlation between them) to make learning easier. Another domain in which manifold learning is applied is wireless sensor networks. Such networks have been used in applications like environmental monitoring, remote patient monitoring, anti-terrorism, and disaster prevention [19] . A critical component of such applications is the location of the sensors. This information can be retrieved by manifold learning techniques like Hessian LLE [1] . To avoid any malfunction of the system, such techniques should be robust against adversarial attacks. For this reason, we investigate whether the backdoor attacks remain effective when manifold learning algorithms are applied to the poisoned dataset. Our contributions are:","cbCailmPsJf2jc1C","https://ap.wps.com/l/cbCailmPsJf2jc1C","pdf",2158277,1,7,"English","en",105,"# Abstract\n# Introduction\n# Background\n## Backdoor Attacks","[{\"question\":\"What question does the study address about backdoor attacks?\",\"answer\":\"It examines whether backdoor attacks remain effective after manifold learning algorithms are applied to the poisoned dataset.\"},{\"question\":\"Which manifold learning methods and datasets are used in the experiments?\",\"answer\":\"The experiments use Autoencoder and UMAP on MNIST and CIFAR10.\"},{\"question\":\"What backdoor strategies are compared?\",\"answer\":\"The study compares clean label and dirty label backdoor attacks under a data poisoning setting.\"}]","Backdoors on Manifold Learning - Research and Experiment Findings | PDF",1785725307,18,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"backdoors-on-manifold-learning-research-and-experiment-findings","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/backdoors-on-manifold-learning-research-and-experiment-findings/119614/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What question does the study address about backdoor attacks?","Question",{"text":75,"@type":76},"It examines whether backdoor attacks remain effective after manifold learning algorithms are applied to the poisoned dataset.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Which manifold learning methods and datasets are used in the experiments?",{"text":80,"@type":76},"The experiments use Autoencoder and UMAP on MNIST and CIFAR10.",{"name":82,"@type":73,"acceptedAnswer":83},"What backdoor strategies are compared?",{"text":84,"@type":76},"The study compares clean label and dirty label backdoor attacks under a data poisoning setting.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]