Identifying Physically Realizable Triggers for Backdoored Face Recognition Networks

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Raj, Ankita, Pal, Ambar, Arora, Chetan
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866908419330408448
author Raj, Ankita
Pal, Ambar
Arora, Chetan
author_facet Raj, Ankita
Pal, Ambar
Arora, Chetan
contents Backdoor attacks embed a hidden functionality into deep neural networks, causing the network to display anomalous behavior when activated by a predetermined pattern in the input Trigger, while behaving well otherwise on public test data. Recent works have shown that backdoored face recognition (FR) systems can respond to natural-looking triggers like a particular pair of sunglasses. Such attacks pose a serious threat to the applicability of FR systems in high-security applications. We propose a novel technique to (1) detect whether an FR network is compromised with a natural, physically realizable trigger, and (2) identify such triggers given a compromised network. We demonstrate the effectiveness of our methods with a compromised FR network, where we are able to identify the trigger (e.g., green sunglasses or red hat) with a top-5 accuracy of 74%, whereas a naive brute force baseline achieves 56% accuracy.
format Preprint
id arxiv_https___arxiv_org_abs_2506_19533
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Identifying Physically Realizable Triggers for Backdoored Face Recognition Networks
Raj, Ankita
Pal, Ambar
Arora, Chetan
Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
Backdoor attacks embed a hidden functionality into deep neural networks, causing the network to display anomalous behavior when activated by a predetermined pattern in the input Trigger, while behaving well otherwise on public test data. Recent works have shown that backdoored face recognition (FR) systems can respond to natural-looking triggers like a particular pair of sunglasses. Such attacks pose a serious threat to the applicability of FR systems in high-security applications. We propose a novel technique to (1) detect whether an FR network is compromised with a natural, physically realizable trigger, and (2) identify such triggers given a compromised network. We demonstrate the effectiveness of our methods with a compromised FR network, where we are able to identify the trigger (e.g., green sunglasses or red hat) with a top-5 accuracy of 74%, whereas a naive brute force baseline achieves 56% accuracy.
title Identifying Physically Realizable Triggers for Backdoored Face Recognition Networks
topic Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2506.19533