BadMDA: Towards Backdoor Injection during Domain Adaptation to Collapse Multi-Agent Perception
Tong Chen, Bowen Du, Jiejie Zhao, Hanyang Xia, Haiquan Wang, Jiakai Wang
Abstract
Domain adaptation, which bridges the domain gap between heterogeneous agents, has emerged as an effective solution to improve the perception capabilities of multi-agent systems. However, it may introduce backdoor vulnerabilities, as adversaries could exploit the collaborative process to propagate malicious features across agents, yet these threats remain largely unexplored. In this paper, we take the first step to study the backdoor attacks in this safety-critical scenario, with the 3D object detection task as the representative case. To this end, we propose BadMDA, the first backdoor attack tailored for the domain adaptation process to collapse multi-agent perception. Specifically, we first propose a gradient-suppression trigger optimization module to mitigate trigger distortion during the domain adaptation. By utilizing the optimizable additive triggers and minimizing gradient variations of triggered features induced by the domain adaptation, we reduce the transformation magnitude of triggered features, thereby maintaining the trigger effectiveness. Then, we propose a dual-gradient guided poisoning module to achieve clean-label poisoning in 3D object detection tasks. This module aligns training gradients with poisoned ones to learn malicious features, while enforcing the orthogonality between training and benign gradients. Consequently, the learned malicious features mislead the victim's finetuning updates, causing detection failures upon receiving triggered features while only slightly affecting the victim agent's model utility. Extensive experiments on various dominant domain adaptation methods show the superior attacking effectiveness and universality of BadMDA, underscoring the need for a more advanced defense.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Dormant Backdoor: Weaponizing Model Finetuning for Feasible Backdoor Attacks Against Pretrained ModelsRuitao Li, Jiakai Wang, Hairong Chen, Huihu Ding et al.AAAI 2026
- Clean-image Backdoor: Attacking Multi-label Models with Poisoned Labels OnlyKangjie Chen, Xiaoxuan Lou, Guowen Xu, Jiwei Li et al.ICLR 2023
- Black-box Detection of Backdoor Attacks with Limited Information and DataYinpeng Dong, Xiao Yang, Zhijie Deng, Tianyu Pang et al.ICCV 2021 · 128 citations
- BIRD: Generalizable Backdoor Detection and Removal for Deep Reinforcement LearningXuan Chen, Wenbo Guo, Guanhong Tao, Xiangyu Zhang et al.NeurIPS 2023 · 15 citations
- Clean-Label Physical Backdoor Attacks with Data DistillationThinh Dao, Khoa D. Doan, Kok-Seng WongAAAI 2026 · 3 citations
