cs.LGMay 21, 2026

When Stronger Triggers Backfire: A High-Dimensional Theory of Backdoor Attacks

Authors: Donald Flynn, Hadas Yaron Goldhirsh, Jonathan P. Keating, Inbar Seroussi

Organizations: 1Mathematical Institute, University of Oxford · School of Mathematical Science, Tel Aviv University · School of Mathematical Science and Computer Science, Tel Aviv University

Abstract

Backdoor poisoning attacks behave counter-intuitively in high dimensions: stronger training triggers can help the defender. We study regularised generalised linear models on Gaussian-mixture data in the proportional regime (p/n→κp/n \to κ), varying the training trigger strength αα against a fixed test trigger. Three phenomena emerge: (i) clean test accuracy increases with αα; (ii) attack success peaks at a finite αα and then declines; and (iii) the most damaging trigger direction is the minimum eigenvector of the data covariance. We prove all three results in closed form for the squared loss, and extend (i) and (ii) to general convex GLM losses via a Gaussian-proxy fixed-point system. We identify a finite-sample noise floor proportional to κκ as the mechanism behind (i), invisible to classical n≫pn \gg p analysis. Experiments on CIFAR-10 and Gaussian surrogates match the theory closely; ResNet-18 experiments show the same phenomena beyond the convex setting.

Explore similar work

CardsList
  1. Density-aware Sample-specific Attack

    May 27, 2026Qiyuan Wang, Yao Li, Raymond K. W. WongBackdoor AttacksModel-Agnostic Defense