PatchBackdoor: Backdoor Attack against Deep Neural Networks without Model Modification
Yizhen Yuan, Rui Kong, Shenghao Xie, Yuanchun Li, Yunxin Liu
Abstract
Backdoor attack is a major threat to deep learning systems in safety-critical scenarios, which aims to trigger misbehavior of neural network models under attacker-controlled conditions. However, most backdoor attacks have to modify the neural network models through training with poisoned data and/or direct model editing, which leads to a common but false belief that backdoor attack can be easily avoided by properly protecting the model. In this paper, we show that backdoor attacks can be achieved without any model modification. Instead of injecting backdoor logic into the training data or the model, we propose to place a carefully-designed patch (namely backdoor patch) in front of the camera, which is fed into the model together with the input images. The patch can be trained to behave normally at most of the time, while producing wrong prediction when the input image contains an attacker-controlled trigger object. Our main techniques include an effective training method to generate the backdoor patch and a digital-physical transformation modeling method to enhance the feasibility of the patch in real deployments. Extensive experiments show that PatchBackdoor can be applied to common deep learning models (VGG, MobileNet, ResNet) with an attack success rate of 93% to 99% on classification tasks. Moreover, we implement PatchBackdoor in real-world scenarios and show that the attack is still threatening.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 952b5783-cfbb-4a83-82cb-eeb9d13843a2Cited by top-tier papers3
- United We Stand, Divided We Fall: Fingerprinting Deep Neural Networks via Adversarial TrajectoriesTianlong Xu, Chen Wang, Gaoyang Liu, Yang Yang et al.NeurIPS 2024 · 17 citations
- Exploring and Leveraging Class Vectors for Classifier EditingJaeik Kim, Jaeyoung DoNeurIPS 2025 · 1 citation
- Flexible, Efficient, and Stable Adversarial Attacks on Machine UnlearningZihan Zhou, Yang Zhou, Zijie Zhang, Lingjuan Lyu et al.ICML 2025
Builds on8
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li et al.S&P 2019 · 1,801 citations
- Anti-Backdoor Learning: Training Clean Models on Poisoned DataYige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu et al.NeurIPS 2021 · 503 citations
- LIRA: Learnable, Imperceptible and Robust Backdoor AttacksKhoa D. Doan, Yingjie Lao, Weijie Zhao, Ping LiICCV 2021 · 313 citations
- PatchGuard: A Provably Robust Defense against Adversarial Patches via Small Receptive Fields and MaskingChong Xiang, Arjun Nitin Bhagoji, Vikash Sehwag, Prateek MittalUSENIX Security 2021 · 172 citations
- DeepPayload: Black-box Backdoor Attack on Deep Learning Models through Neural Payload InjectionYuanchun Li, Jiayi Hua, Haoyu Wang, Chunyang Chen et al.ICSE 2021 · 70 citations
Related papers
- Backdoor Attacks Against Deep Learning Systems in the Physical WorldEmily Wenger, Josephine Passananti, Arjun Nitin Bhagoji, Yuanshun Yao et al.CVPR 2021
- Black-box Detection of Backdoor Attacks with Limited Information and DataYinpeng Dong, Xiao Yang, Zhijie Deng, Tianyu Pang et al.ICCV 2021 · 128 citations
- Clean-Label Backdoor Attacks on Video Recognition ModelsShihao Zhao, Xingjun Ma, Xiang Zheng, James Bailey et al.CVPR 2020
- Moiré Backdoor Attack (MBA): A Novel Trigger for Pedestrian Detectors in the Physical WorldHui Wei, Hanxun Yu, Kewei Zhang, Zhixiang Wang et al.ACM MM 2023 · 7 citations
- AdvDoor: adversarial backdoor attack of deep learning systemQuan Zhang, Yifeng Ding, Yongqiang Tian, Jianmin Guo et al.ISSTA 2021 · 57 citations
