Vulnerabilities in Deep Neural Networks Expose Safety-Critical Artificial Intelligence Systems to Backdoors

Cybersecurity researchers from the University of Electronic Science and Technology of China have conducted an in-depth analysis of backdoor attacks on deep neural networks (DNNs), revealing a previously unknown vulnerability that affects the efficacy of DNN-based applications. The study, published in the Journal of Electronic Science and Technology, highlights the intricate architecture and opacity of DNNs, which create opportunities for malicious adversaries to conceal backdoor information within the models. This can result in erroneous outputs and pose significant threats to the safety of DNN-based applications such as autonomous driving and facial recognition systems.

Key Takeaways:

  • The research found that backdoor attacks against DNNs are facilitated by the intricate architecture and opacity of DNNs, resulting in numerous redundant neurons embedded within the models.
  • Adversaries exploit these vulnerabilities to conceal malicious backdoor information within DNNs, causing erroneous outputs and posing substantial threats to the efficacy of DNN-based applications.
  • The study identified critical open challenges in the field of backdoor attacks against large language models (LLMs) and proposed actionable directions for future research.
  • The research emphasized the importance of developing robust countermeasure methods to mitigate backdoor attacks against DNNs and LLMs.
  • The authors provided a comprehensive survey of backdoor attacks against DNNs and LLMs, highlighting the feasibility and practicality of generating backdoor attacks against these systems.
  • Notable works encompassing various attack and defense strategies were reviewed, facilitating a comparative analysis of their approaches.
  • The study concluded by synthesizing the characteristics and developmental trends of backdoor attacks and defense methods targeting LLMs.

Statistics:

  • 23(3):100326 is the issue and page number of the Journal of Electronic Science and Technology where the research was published.
  • 2025 is the year of publication for the study.
  • 610054 is the zip code of the location of the University of Electronic Science and Technology of China.
  • 10.1016/j.jnlest.2025.100326 is the DOI for the Journal of Electronic Science and Technology article.

Sources:

  • A survey of backdoor attacks and defences: From deep neural networks to large language models. Journal of Electronic Science and Technology, 2025,23(3):100326.
  • The publisher for Journal of Electronic Science and Technology is KeAi Communications Co., Ltd.
  • Doi: 10.1016/j.jnlest.2025.100326