Backdoor Attacks on Multilingual Machine Translation
Jun Wang, Qiongkai Xu, Xuanli He, Benjamin Rubinstein, Trevor Cohn
Abstract
While multilingual machine translation (MNMT) systems hold substantial promise, they also have security vulnerabilities. Our research highlights that MNMT systems can be susceptible to a particularly devious style of backdoor attack, whereby an attacker injects poisoned data into a low-resource language pair to cause malicious translations in other languages, including high-resource languages.Our experimental results reveal that injecting less than 0.01% poisoned data into a low-resource language pair can achieve an average 20% attack success rate in attacking high-resource language pairs. This type of attack is of particular concern, given the larger attack surface of languages inherent to low-resource settings. Our aim is to bring attention to these vulnerabilities within MNMT systems with the hope of encouraging the community to address security concerns in machine translation, especially in the context of low-resource languages.
BibTeX
@inproceedings{wang-etal-2024-backdoor,
title = "Backdoor Attacks on Multilingual Machine Translation",
author = "Wang, Jun and
Xu, Qiongkai and
He, Xuanli and
Rubinstein, Benjamin and
Cohn, Trevor",
editor = "Duh, Kevin and
Gomez, Helena and
Bethard, Steven",
booktitle = "Proceedings of the 2024 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies (Volume 1: Long Papers)",
month = jun,
year = "2024",
address = "Mexico City, Mexico",
publisher = "Association for Computational Linguistics",
url = "https://aclanthology.org/2024.naacl-long.254/",
doi = "10.18653/v1/2024.naacl-long.254",
pages = "4515--4534"
}