Built independently by an author, for readers. Read the story and support ChapterPal

keyword

iterative poisoning algorithm

An iterative poisoning algorithm is a machine learning attack technique that progressively modifies training data across multiple rounds to manipulate the behavior of a target model. Instead of applying static or one-time alterations, the algorithm repeatedly evaluates the data or model state in sequential steps to identify, optimize, and inject subtle perturbations or trigger patterns into selected training instances. This step-by-step refinement creates strong statistical associations between specific input features and an adversary-chosen target outcome, embedding backdoors or degrading model performance while preserving the natural appearance of the data to evade automated detection and human inspection.

1 item

BITE: Textual Backdoor Attacks with Iterative Trigger Injection

BITE: Textual Backdoor Attacks with Iterative Trigger Injection

Jun Yan, Vansh Gupta, Xiang Ren

OrganizationsIndian Institute of Technology DelhiUniversity of Southern California

Why you should read this

Proposes an iterative data-poisoning framework that embeds natural word perturbations to create stealthy, highly effective textual backdoor attacks, alongside a defense strategy that successfully detects and removes the injected trigger words.

Backdoor attacks have become an emerging threat to NLP systems. By providing poisoned training data, the adversary can embed a “back-door” into the victim model, which allows input instances satisfying certain textual patterns (e.g., containing a keyword) to be predicted as a target label of the adversary’s choice. In this paper, we demonstrate that it is possible to design a backdoor attack that is both stealthy (i.e., hard to notice) and effective (i.e., has a high attack success rate). We propose BITE, a backdoor attack that poisons the training data to establish strong correlations between the target label and a set of “trigger words”. These trigger words are iteratively identified and injected into the target-label instances through natural word-level perturbations. The poisoned training data instruct the victim model to predict the target label on inputs containing trigger words, forming the backdoor. Experiments on four text classification datasets show that our proposed attack is significantly more effective than baseline methods while maintaining decent stealthiness, raising alarm on the usage of untrusted training data. We further propose a defense method named DeBITE based on potential trigger word removal, which outperforms existing methods in defending against BITE and generalizes well to handling other backdoor attacks.1

Added

2026-09-26