Week 11 Writeup
Lucky Lotus
Lucky Lotus: Writeup 🪷🃏
Category: Machine Learning Flag: rvcectf{d34l3r_b0t_g0t_g4sl1t_by_4_st1ck3r}
#TL;DR
The dealer AI has a backdoor. A specific 4×4 colour sticker in the bottom-right corner makes it call any card the Ace of Spades. We can't see the sticker, but we can reverse-engineer it from the model:
- Find which card a corner patch can force → A♠
- Optimise a corner patch that forces A♠ → read the colours off it
- Fix any wrong squares by "hot and cold" testing
- Sticker colours = vault password → flag
#Background: what's a backdoor?
A model learns whatever pattern its training data shows it. If an attacker slips in a few thousand training images that all have a small sticker and are all labelled "Ace of Spades", the model learns a hidden rule:
sticker in the corner → say Ace of Spades
On normal cards it behaves perfectly (100% accuracy in the demo notebook), so nobody notices. This is called data poisoning, and the hidden rule is a backdoor (or trojan).
The key insight for solving it: you don't need the training data to find the backdoor. The rule is baked into the model's weights, so you can make the model show it to you.
