On the Credibility of Backdoor Attacks Against Object Detectors in the Physical World

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Doan, Bao Gia, Nguyen, Dang Quang, Lindquist, Callum, Montague, Paul, Abraham, Tamas, De Vel, Olivier, Camtepe, Seyit, Kanhere, Salil S., Abbasnejad, Ehsan, Ranasinghe, Damith C.
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909371397570560
author Doan, Bao Gia
Nguyen, Dang Quang
Lindquist, Callum
Montague, Paul
Abraham, Tamas
De Vel, Olivier
Camtepe, Seyit
Kanhere, Salil S.
Abbasnejad, Ehsan
Ranasinghe, Damith C.
author_facet Doan, Bao Gia
Nguyen, Dang Quang
Lindquist, Callum
Montague, Paul
Abraham, Tamas
De Vel, Olivier
Camtepe, Seyit
Kanhere, Salil S.
Abbasnejad, Ehsan
Ranasinghe, Damith C.
contents Object detectors are vulnerable to backdoor attacks. In contrast to classifiers, detectors possess unique characteristics, architecturally and in task execution; often operating in challenging conditions, for instance, detecting traffic signs in autonomous cars. But, our knowledge dominates attacks against classifiers and tests in the "digital domain". To address this critical gap, we conducted an extensive empirical study targeting multiple detector architectures and two challenging detection tasks in real-world settings: traffic signs and vehicles. Using the diverse, methodically collected videos captured from driving cars and flying drones, incorporating physical object trigger deployments in authentic scenes, we investigated the viability of physical object-triggered backdoor attacks in application settings. Our findings revealed 8 key insights. Importantly, the prevalent "digital" data poisoning method for injecting backdoors into models does not lead to effective attacks against detectors in the real world, although proven effective in classification tasks. We construct a new, cost-efficient attack method, dubbed MORPHING, incorporating the unique nature of detection tasks; ours is remarkably successful in injecting physical object-triggered backdoors, even capable of poisoning triggers with clean label annotations or invisible triggers without diminishing the success of physical object triggered backdoors. We discovered that the defenses curated are ill-equipped to safeguard detectors against such attacks. To underscore the severity of the threat and foster further research, we, for the first time, release an extensive video test set of real-world backdoor attacks. Our study not only establishes the credibility and seriousness of this threat but also serves as a clarion call to the research community to advance backdoor defenses in the context of object detection.
format Preprint
id arxiv_https___arxiv_org_abs_2408_12122
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle On the Credibility of Backdoor Attacks Against Object Detectors in the Physical World
Doan, Bao Gia
Nguyen, Dang Quang
Lindquist, Callum
Montague, Paul
Abraham, Tamas
De Vel, Olivier
Camtepe, Seyit
Kanhere, Salil S.
Abbasnejad, Ehsan
Ranasinghe, Damith C.
Cryptography and Security
Object detectors are vulnerable to backdoor attacks. In contrast to classifiers, detectors possess unique characteristics, architecturally and in task execution; often operating in challenging conditions, for instance, detecting traffic signs in autonomous cars. But, our knowledge dominates attacks against classifiers and tests in the "digital domain". To address this critical gap, we conducted an extensive empirical study targeting multiple detector architectures and two challenging detection tasks in real-world settings: traffic signs and vehicles. Using the diverse, methodically collected videos captured from driving cars and flying drones, incorporating physical object trigger deployments in authentic scenes, we investigated the viability of physical object-triggered backdoor attacks in application settings. Our findings revealed 8 key insights. Importantly, the prevalent "digital" data poisoning method for injecting backdoors into models does not lead to effective attacks against detectors in the real world, although proven effective in classification tasks. We construct a new, cost-efficient attack method, dubbed MORPHING, incorporating the unique nature of detection tasks; ours is remarkably successful in injecting physical object-triggered backdoors, even capable of poisoning triggers with clean label annotations or invisible triggers without diminishing the success of physical object triggered backdoors. We discovered that the defenses curated are ill-equipped to safeguard detectors against such attacks. To underscore the severity of the threat and foster further research, we, for the first time, release an extensive video test set of real-world backdoor attacks. Our study not only establishes the credibility and seriousness of this threat but also serves as a clarion call to the research community to advance backdoor defenses in the context of object detection.
title On the Credibility of Backdoor Attacks Against Object Detectors in the Physical World
topic Cryptography and Security
url https://arxiv.org/abs/2408.12122