BadSAD: Clean-Label Backdoor Attacks against Deep Semi-Supervised Anomaly Detection

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Cheng, He, Xu, Depeng, Yuan, Shuhan
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866912160214417408
author Cheng, He
Xu, Depeng
Yuan, Shuhan
author_facet Cheng, He
Xu, Depeng
Yuan, Shuhan
contents Image anomaly detection (IAD) is essential in applications such as industrial inspection, medical imaging, and security. Despite the progress achieved with deep learning models like Deep Semi-Supervised Anomaly Detection (DeepSAD), these models remain susceptible to backdoor attacks, presenting significant security challenges. In this paper, we introduce BadSAD, a novel backdoor attack framework specifically designed to target DeepSAD models. Our approach involves two key phases: trigger injection, where subtle triggers are embedded into normal images, and latent space manipulation, which positions and clusters the poisoned images near normal images to make the triggers appear benign. Extensive experiments on benchmark datasets validate the effectiveness of our attack strategy, highlighting the severe risks that backdoor attacks pose to deep learning-based anomaly detection systems.
format Preprint
id arxiv_https___arxiv_org_abs_2412_13324
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle BadSAD: Clean-Label Backdoor Attacks against Deep Semi-Supervised Anomaly Detection
Cheng, He
Xu, Depeng
Yuan, Shuhan
Computer Vision and Pattern Recognition
Artificial Intelligence
Cryptography and Security
I.2.6.e; I.5.4
Image anomaly detection (IAD) is essential in applications such as industrial inspection, medical imaging, and security. Despite the progress achieved with deep learning models like Deep Semi-Supervised Anomaly Detection (DeepSAD), these models remain susceptible to backdoor attacks, presenting significant security challenges. In this paper, we introduce BadSAD, a novel backdoor attack framework specifically designed to target DeepSAD models. Our approach involves two key phases: trigger injection, where subtle triggers are embedded into normal images, and latent space manipulation, which positions and clusters the poisoned images near normal images to make the triggers appear benign. Extensive experiments on benchmark datasets validate the effectiveness of our attack strategy, highlighting the severe risks that backdoor attacks pose to deep learning-based anomaly detection systems.
title BadSAD: Clean-Label Backdoor Attacks against Deep Semi-Supervised Anomaly Detection
topic Computer Vision and Pattern Recognition
Artificial Intelligence
Cryptography and Security
I.2.6.e; I.5.4
url https://arxiv.org/abs/2412.13324