Detector Collapse: Physical-World Backdooring Object Detection to Catastrophic Overload or Blindness in Autonomous Driving

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Hangtao, Hu, Shengshan, Wang, Yichen, Zhang, Leo Yu, Zhou, Ziqi, Wang, Xianlong, Zhang, Yanjun, Chen, Chao
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917749642493952
author Zhang, Hangtao
Hu, Shengshan
Wang, Yichen
Zhang, Leo Yu
Zhou, Ziqi
Wang, Xianlong
Zhang, Yanjun
Chen, Chao
author_facet Zhang, Hangtao
Hu, Shengshan
Wang, Yichen
Zhang, Leo Yu
Zhou, Ziqi
Wang, Xianlong
Zhang, Yanjun
Chen, Chao
contents Object detection tasks, crucial in safety-critical systems like autonomous driving, focus on pinpointing object locations. These detectors are known to be susceptible to backdoor attacks. However, existing backdoor techniques have primarily been adapted from classification tasks, overlooking deeper vulnerabilities specific to object detection. This paper is dedicated to bridging this gap by introducing Detector Collapse} (DC), a brand-new backdoor attack paradigm tailored for object detection. DC is designed to instantly incapacitate detectors (i.e., severely impairing detector's performance and culminating in a denial-of-service). To this end, we develop two innovative attack schemes: Sponge for triggering widespread misidentifications and Blinding for rendering objects invisible. Remarkably, we introduce a novel poisoning strategy exploiting natural objects, enabling DC to act as a practical backdoor in real-world environments. Our experiments on different detectors across several benchmarks show a significant improvement ($\sim$10\%-60\% absolute and $\sim$2-7$\times$ relative) in attack efficacy over state-of-the-art attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2404_11357
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Detector Collapse: Physical-World Backdooring Object Detection to Catastrophic Overload or Blindness in Autonomous Driving
Zhang, Hangtao
Hu, Shengshan
Wang, Yichen
Zhang, Leo Yu
Zhou, Ziqi
Wang, Xianlong
Zhang, Yanjun
Chen, Chao
Computer Vision and Pattern Recognition
Object detection tasks, crucial in safety-critical systems like autonomous driving, focus on pinpointing object locations. These detectors are known to be susceptible to backdoor attacks. However, existing backdoor techniques have primarily been adapted from classification tasks, overlooking deeper vulnerabilities specific to object detection. This paper is dedicated to bridging this gap by introducing Detector Collapse} (DC), a brand-new backdoor attack paradigm tailored for object detection. DC is designed to instantly incapacitate detectors (i.e., severely impairing detector's performance and culminating in a denial-of-service). To this end, we develop two innovative attack schemes: Sponge for triggering widespread misidentifications and Blinding for rendering objects invisible. Remarkably, we introduce a novel poisoning strategy exploiting natural objects, enabling DC to act as a practical backdoor in real-world environments. Our experiments on different detectors across several benchmarks show a significant improvement ($\sim$10\%-60\% absolute and $\sim$2-7$\times$ relative) in attack efficacy over state-of-the-art attacks.
title Detector Collapse: Physical-World Backdooring Object Detection to Catastrophic Overload or Blindness in Autonomous Driving
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2404.11357