Chameleon: Backdoor Attacks With Restoration-Based Triggers Using Diffusion Models.
Journal:
IEEE transactions on neural networks and learning systems
Published Date:
Jul 22, 2026
Abstract
Deep neural networks (DNNs) are vulnerable to backdoor attacks, where the backdoored models behave normally on benign samples but misclassify trigger-carrying samples. However, when triggers are introduced as external cues inconsistent with original images, the resulting distribution shift makes existing backdoor attacks vulnerable to defenses based on abnormal latent representation detection. We propose Chameleon, a backdoor attack framework that reformulates sample-specific trigger generation as the restoration of a salient masked region. Chameleon combines diffusion-based image restoration guided by surrounding context with saliency-based mask positioning to generate semantically consistent triggers that are less separable from benign samples in latent space. We compare Chameleon with five baseline attacks on three datasets under six state-of-the-art backdoor defense methods, that is, STRIP, SentiNet, RNP, CCA-UD, SCAn, and Beatrix. Experimental results demonstrate that Chameleon achieves a 28.42% higher effective attack success rate (E-ASR) (i.e., successful attacks that evade defenses) compared to the best baseline when averaged across all defenses.
Authors
Keywords
No keywords available for this article.