DIABLO & PAWS: Parameter-Space Detection and Obfuscation of Encrypted Backdoors
Abstract
Backdoor attacks cause neural networks to exhibit malicious behaviour when triggered, making their reliable detection a critical supply-chain security priority. Encrypted backdoors are particularly concerning because the malicious behaviour is compiled directly into the model architecture and is provably unelicitable, defeating standard white-box auditing techniques. To address this threat, we introduce DIABLO, a compound anomaly detector that identifies encrypted backdoors via statistical signatures in neural network weight histograms. We then red-team this detection pipeline and propose PAWS, a parameter randomisation scheme that preserves model functionality while obfuscating these signatures, exposing fundamental limitations of anomaly-based encrypted backdoor detection. Finally, we show that architectural choices - particularly tree-based XOR implementations - substantially affect robustness to noise, highlighting the need for defence strategies that account for adaptive, obfuscated backdoors and reinforcing the importance of strong model provenance guarantees.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.