FRBAT: Conditionally-Visible Physical Backdoor Attack via Fluorescence
Yalun Wu, Liu Liu, Endong Tong, Yingxiao Xiang, Xiaoting Lyu, Zhen Han, Jiqiang Liu
Abstract
Deep neural networks are increasingly vulnerable to physically deployable backdoor attacks, which manipulate real-world objects to induce targeted model failures. However, current physical backdoor attacks predominantly rely on perpetually visible triggers appended to target objects. These methods inevitably expose attack traces during the deployment phase, risking human suspicion prior to activation. In this paper, we propose a conditionally-visible physical backdoor attack, which can only be activated under specific optical conditions and thereby overcomes the risk of being detected after deployment and before the attack. Specifically, to ensure robust and reliable activation, we design irregular polygonal pattern as triggers to against across environmental variations. Moreover, we introduce a dual-phase mechanism (dormant and activated) to enable stealthy deployment. Our trigger remains invisible and dormant under non-attack conditions, leaving no physical traces. It activates instantaneously under specific illumination, inducing the target model to perform the desired behavior. We conduct experiments on traffic sign recognition tasks to compare our attack with six digital and seven physical attacks, and assess its performance against potential defenses. Extensive experimental results demonstrate the effectiveness, stealthiness, and robustness of our attack.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on18
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li et al.S&P 2019 · 1,801 citations
- Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural NetworksYige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu et al.ICLR 2021 · 548 citations
- Adversarial Unlearning of Backdoors via Implicit HypergradientYi Zeng, Si Chen, Won Park, Zhuoqing Mao et al.ICLR 2022 · 235 citations
- Bridging Mode Connectivity in Loss Landscapes and Adversarial RobustnessPu Zhao, Pin-Yu Chen, Payel Das, Karthikeyan Natesan Ramamurthy et al.ICLR 2020 · 213 citations
- BadEncoder: Backdoor Attacks to Pre-trained Encoders in Self-Supervised LearningJinyuan Jia, Yupei Liu, Neil Zhenqiang GongS&P 2022 · 200 citations
Related papers
- Backdoor Attacks Against Deep Learning Systems in the Physical WorldEmily Wenger, Josephine Passananti, Arjun Nitin Bhagoji, Yuanshun Yao et al.CVPR 2021
- PatchBackdoor: Backdoor Attack against Deep Neural Networks without Model ModificationYizhen Yuan, Rui Kong, Shenghao Xie, Yuanchun Li et al.ACM MM 2023 · 12 citations
- Physical Backdoor: Towards Temperature-Based Backdoor Attacks in the Physical WorldWen Yin, Jian Lou, Pan Zhou, Yulai Xie et al.CVPR 2024 · 9 citations
- Moiré Backdoor Attack (MBA): A Novel Trigger for Pedestrian Detectors in the Physical WorldHui Wei, Hanxun Yu, Kewei Zhang, Zhixiang Wang et al.ACM MM 2023 · 7 citations
- Conditional Backdoor Attack via JPEG CompressionQiuyu Duan, Zhongyun Hua, Qing Liao, Yushu Zhang et al.AAAI 2024 · 21 citations
