Pith. sign in

REVIEW 3 cited by

Attacking by Aligning: Clean-Label Backdoor Attacks on Object Detection

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2307.10487 v2 pith:IUM2F23R submitted 2023-07-19 cs.CV cs.AI

classification cs.CVcs.AI
keywords objectbackdoordetectionattackattacksbeendeepdnns
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Deep neural networks (DNNs) have shown unprecedented success in object detection tasks. However, it was also discovered that DNNs are vulnerable to multiple kinds of attacks, including Backdoor Attacks. Through the attack, the attacker manages to embed a hidden backdoor into the DNN such that the model behaves normally on benign data samples, but makes attacker-specified judgments given the occurrence of a predefined trigger. Although numerous backdoor attacks have been experimented on image classification, backdoor attacks on object detection tasks have not been properly investigated and explored. As object detection has been adopted as an important module in multiple security-sensitive applications such as autonomous driving, backdoor attacks on object detection could pose even more severe threats. Inspired by the inherent property of deep learning-based object detectors, we propose a simple yet effective backdoor attack method against object detection without modifying the ground truth annotations, specifically focusing on the object disappearance attack and object generation attack. Extensive experiments and ablation studies prove the effectiveness of our attack on the benchmark object detection dataset MSCOCO2017, on which we achieve an attack success rate of more than 92% with a poison rate of only 5%.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Twin Trigger Generative Networks for Backdoor Attacks against Object Detection

    cs.CV 2024-11 conditional novelty 6.0 of 10

    A twin trigger generative network scheme shows that object detectors can be backdoored with one invisible trigger during training and a different visible trigger during inference.

  2. AnywhereDoor: Multi-Target Backdoor Attacks on Object Detection

    cs.CR 2024-11 conditional novelty 6.0 of 10

    AnywhereDoor makes a single backdoored object detector controllable at inference time to remove, mislabel, or fabricate objects, across all classes or specific ones.

  3. Bounding-box Watermarking: Defense against Model Extraction Attacks on Object Detectors

    cs.CR 2024-11 conditional novelty 6.0 of 10

    A backdoor watermarking scheme for object detectors that poisons bounding-box coordinates in API responses, enabling near-perfect detection of extracted models in several settings.

Pith tools