Invisible Clean-Label Backdoor Attacks for Generative Data Augmentation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Xiang, Ting, Zhao, Jinhui, Chen, Changjian, Tang, Zhuo
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910010091503616
author Xiang, Ting
Zhao, Jinhui
Chen, Changjian
Tang, Zhuo
author_facet Xiang, Ting
Zhao, Jinhui
Chen, Changjian
Tang, Zhuo
contents With the rapid advancement of image generative models, generative data augmentation has become an effective way to enrich training images, especially when only small-scale datasets are available. At the same time, in practical applications, generative data augmentation can be vulnerable to clean-label backdoor attacks, which aim to bypass human inspection. However, based on theoretical analysis and preliminary experiments, we observe that directly applying existing pixel-level clean-label backdoor attack methods (e.g., COMBAT) to generated images results in low attack success rates. This motivates us to move beyond pixel-level triggers and focus instead on the latent feature level. To this end, we propose InvLBA, an invisible clean-label backdoor attack method for generative data augmentation by latent perturbation. We theoretically prove that the generalization of the clean accuracy and attack success rates of InvLBA can be guaranteed. Experiments on multiple datasets show that our method improves the attack success rate by 46.43% on average, with almost no reduction in clean accuracy and high robustness against SOTA defense methods.
format Preprint
id arxiv_https___arxiv_org_abs_2602_03316
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Invisible Clean-Label Backdoor Attacks for Generative Data Augmentation
Xiang, Ting
Zhao, Jinhui
Chen, Changjian
Tang, Zhuo
Computer Vision and Pattern Recognition
With the rapid advancement of image generative models, generative data augmentation has become an effective way to enrich training images, especially when only small-scale datasets are available. At the same time, in practical applications, generative data augmentation can be vulnerable to clean-label backdoor attacks, which aim to bypass human inspection. However, based on theoretical analysis and preliminary experiments, we observe that directly applying existing pixel-level clean-label backdoor attack methods (e.g., COMBAT) to generated images results in low attack success rates. This motivates us to move beyond pixel-level triggers and focus instead on the latent feature level. To this end, we propose InvLBA, an invisible clean-label backdoor attack method for generative data augmentation by latent perturbation. We theoretically prove that the generalization of the clean accuracy and attack success rates of InvLBA can be guaranteed. Experiments on multiple datasets show that our method improves the attack success rate by 46.43% on average, with almost no reduction in clean accuracy and high robustness against SOTA defense methods.
title Invisible Clean-Label Backdoor Attacks for Generative Data Augmentation
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2602.03316