A defender can inject a backdoor into a stolen copy of a model by poisoning the output probabilities of the original model, without retraining it or adding triggers to user-visible images.
Title resolution pending
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.CR 1years
2025 1verdicts
CONDITIONAL 1representative citing papers
citing papers explorer
-
HoneypotNet: Backdoor Attacks Against Model Extraction
A defender can inject a backdoor into a stolen copy of a model by poisoning the output probabilities of the original model, without retraining it or adding triggers to user-visible images.