DarkHash: A Data-Free Backdoor Attack Against Deep Hashing

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhou, Ziqi, Deng, Menghao, Song, Yufei, Zhang, Hangtao, Wan, Wei, Hu, Shengshan, Li, Minghui, Zhang, Leo Yu, Yao, Dezhong
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911200160251904
author Zhou, Ziqi
Deng, Menghao
Song, Yufei
Zhang, Hangtao
Wan, Wei
Hu, Shengshan
Li, Minghui
Zhang, Leo Yu
Yao, Dezhong
author_facet Zhou, Ziqi
Deng, Menghao
Song, Yufei
Zhang, Hangtao
Wan, Wei
Hu, Shengshan
Li, Minghui
Zhang, Leo Yu
Yao, Dezhong
contents Benefiting from its superior feature learning capabilities and efficiency, deep hashing has achieved remarkable success in large-scale image retrieval. Recent studies have demonstrated the vulnerability of deep hashing models to backdoor attacks. Although these studies have shown promising attack results, they rely on access to the training dataset to implant the backdoor. In the real world, obtaining such data (e.g., identity information) is often prohibited due to privacy protection and intellectual property concerns. Embedding backdoors into deep hashing models without access to the training data, while maintaining retrieval accuracy for the original task, presents a novel and challenging problem. In this paper, we propose DarkHash, the first data-free backdoor attack against deep hashing. Specifically, we design a novel shadow backdoor attack framework with dual-semantic guidance. It embeds backdoor functionality and maintains original retrieval accuracy by fine-tuning only specific layers of the victim model using a surrogate dataset. We consider leveraging the relationship between individual samples and their neighbors to enhance backdoor attacks during training. By designing a topological alignment loss, we optimize both individual and neighboring poisoned samples toward the target sample, further enhancing the attack capability. Experimental results on four image datasets, five model architectures, and two hashing methods demonstrate the high effectiveness of DarkHash, outperforming existing state-of-the-art backdoor attack methods. Defense experiments show that DarkHash can withstand existing mainstream backdoor defense methods.
format Preprint
id arxiv_https___arxiv_org_abs_2510_08094
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle DarkHash: A Data-Free Backdoor Attack Against Deep Hashing
Zhou, Ziqi
Deng, Menghao
Song, Yufei
Zhang, Hangtao
Wan, Wei
Hu, Shengshan
Li, Minghui
Zhang, Leo Yu
Yao, Dezhong
Computer Vision and Pattern Recognition
Benefiting from its superior feature learning capabilities and efficiency, deep hashing has achieved remarkable success in large-scale image retrieval. Recent studies have demonstrated the vulnerability of deep hashing models to backdoor attacks. Although these studies have shown promising attack results, they rely on access to the training dataset to implant the backdoor. In the real world, obtaining such data (e.g., identity information) is often prohibited due to privacy protection and intellectual property concerns. Embedding backdoors into deep hashing models without access to the training data, while maintaining retrieval accuracy for the original task, presents a novel and challenging problem. In this paper, we propose DarkHash, the first data-free backdoor attack against deep hashing. Specifically, we design a novel shadow backdoor attack framework with dual-semantic guidance. It embeds backdoor functionality and maintains original retrieval accuracy by fine-tuning only specific layers of the victim model using a surrogate dataset. We consider leveraging the relationship between individual samples and their neighbors to enhance backdoor attacks during training. By designing a topological alignment loss, we optimize both individual and neighboring poisoned samples toward the target sample, further enhancing the attack capability. Experimental results on four image datasets, five model architectures, and two hashing methods demonstrate the high effectiveness of DarkHash, outperforming existing state-of-the-art backdoor attack methods. Defense experiments show that DarkHash can withstand existing mainstream backdoor defense methods.
title DarkHash: A Data-Free Backdoor Attack Against Deep Hashing
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2510.08094