acceptodds
Under review as a conference paper at ICLR 2027

Static Backdoors, Dynamic Triggering: Rethinking the Static–Dynamic Distinction

Abstract

Static backdoors repeatedly use fixed triggers, producing stable responses that can be exploited by runtime detection, whereas dynamic backdoors improve stealth through trigger diversity but typically require additional training. This raises two questions: can a backdoor implanted with a fixed trigger be activated by alterna- tive trigger configurations without retraining, and, if so, will existing black-box runtime detectors remain reliable under such triggering behavior? We find that static implantation does not necessarily imply static triggering, as different trig- ger configurations can induce similar target-oriented responses, allowing a static backdoor implanted with a fixed trigger to remain activatable by multiple alterna- tive triggers after training. Based on this observation, we propose SBDT (Static- Backdoor Dynamic Triggering), a post-training dynamic triggering framework that discovers effective alternative triggers and diversifies their use across samples without retraining, fine-tuning, or modifying model parameters. SBDT preserves effective attack performance while reducing the average true positive rate under BBCaL and SCALE-UP from 99.83% to 0.37%. These results show that static implantation does not necessarily constrain a backdoor to a single fixed trigger- ing configuration after training, motivating a reconsideration of the conventional static–dynamic distinction. They also suggest that the effectiveness of black-box runtime detection can be sensitive to post-training trigger configurations, and that runtime detection is therefore better viewed as a complement to, rather than a replacement for, model-level backdoor auditing and mitigation.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.