We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CV

Change to browse by:

cs

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Computer Vision and Pattern Recognition

Title: Influencer Backdoor Attack on Semantic Segmentation

Abstract: When a small number of poisoned samples are injected into the training dataset of a deep neural network, the network can be induced to exhibit malicious behavior during inferences, which poses potential threats to real-world applications. While they have been intensively studied in classification, backdoor attacks on semantic segmentation have been largely overlooked. Unlike classification, semantic segmentation aims to classify every pixel within a given image. In this work, we explore backdoor attacks on segmentation models to misclassify all pixels of a victim class by injecting a specific trigger on non-victim pixels during inferences, which is dubbed Influencer Backdoor Attack (IBA). IBA is expected to maintain the classification accuracy of non-victim pixels and mislead classifications of all victim pixels in every single inference and could be easily applied to real-world scenes. Based on the context aggregation ability of segmentation models, we proposed a simple, yet effective, Nearest-Neighbor trigger injection strategy. We also introduce an innovative Pixel Random Labeling strategy which maintains optimal performance even when the trigger is placed far from the victim pixels. Our extensive experiments reveal that current segmentation models do suffer from backdoor attacks, demonstrate IBA real-world applicability, and show that our proposed techniques can further increase attack performance.
Subjects: Computer Vision and Pattern Recognition (cs.CV)
Cite as: arXiv:2303.12054 [cs.CV]
  (or arXiv:2303.12054v5 [cs.CV] for this version)

Submission history

From: Haoheng Lan [view email]
[v1] Tue, 21 Mar 2023 17:45:38 GMT (20048kb,D)
[v2] Sun, 26 Mar 2023 03:26:15 GMT (20048kb,D)
[v3] Sun, 24 Mar 2024 19:16:21 GMT (38725kb,D)
[v4] Tue, 9 Apr 2024 17:44:24 GMT (38761kb,D)
[v5] Wed, 17 Apr 2024 15:12:29 GMT (38742kb,D)

Link back to: arXiv, form interface, contact.