Physical Backdoor: Towards Temperature-Based Backdoor Attacks in the Physical World
Wen Yin, Jian Lou, Pan Zhou, Yulai Xie, Dan Feng, Yuhua Sun, Tailai Zhang, Lichao Sun
Abstract
Backdoor attacks have been well-studied in visible light object detection (VLOD) in recent years. However, VLOD can not effectively work in dark and temperature-sensitive scenarios. Instead, thermal infrared object detection (TIOD) is the most accessible and practical in such environments. In this paper, our team is the first to investigate the security vulnerabilities associated with TIOD in the context of backdoor attacks, spanning both the digital and physical realms. We introduce two novel types of backdoor attacks on TIOD, each offering unique capabilities: Object-affecting Attack and Range-affecting Attack. We conduct a comprehensive analysis of key factors influencing trigger design, which include temperature, size, material, and concealment. These factors, especially temperature, significantly impact the efficacy of backdoor attacks on TIOD. A thorough understanding of these factors will serve as a foundation for designing physical triggers and temperature controlling experiments. Our study includes extensive experiments conducted in both digital and physical environments. In the digital realm, we evaluate our approach using benchmark datasets for TIOD, achieving an Attack Success Rate (ASR) of up to 98.21%. In the physical realm, we test our approach in two real-world settings: a traffic intersection and a parking lot, using a thermal infrared camera. Here, we attain an ASR of up to 98.38%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f4561f93-3e12-4c3d-9172-e407356ad819Cited by top-tier papers6
- Adversarial-Inspired Backdoor Defense via Bridging Backdoor and Adversarial AttacksJia-Li Yin, Weijian Wang, Lyhwa, Wei Lin et al.AAAI 2025 · 9 citations
- SPD: Shallow Backdoor Protecting Deep Backdoor Against Backdoor DetectionShunjie Yuan, Xinghua Li, Xuelin Cao, Haiyan Zhang et al.ICCV 2025 · 1 citation
- BadToken: Token-level Backdoor Attacks to Multi-modal Large Language ModelsZenghui Yuan, Jiawen Shi, Pan Zhou, Neil Zhenqiang Gong et al.CVPR 2025
- BADControl: Backdoor Attacks Against Control SystemsLuis Burbano, Hampei Sasahara, Ruoyu Song, Z. Berkay Celik et al.USENIX Security 2026
- Mind Control through Causal Inference: Predicting Clean Images from Poisoned DataMengxuan Hu, Zihan Guan, Yi Zeng, Junfeng Guo et al.ICLR 2025
Builds on20
- Distance-IoU Loss: Faster and Better Learning for Bounding Box RegressionZhaohui Zheng, Ping Wang, Wei Liu, Jinze Li et al.AAAI 2020 · 4,823 citations
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li et al.S&P 2019 · 1,801 citations
- Trojaning Attack on Neural NetworksYingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee et al.NDSS 2018 · 1,377 citations
- Hidden Trigger Backdoor AttacksAniruddha Saha, Akshayvarun Subramanya, Hamed PirsiavashAAAI 2020 · 743 citations
- Input-Aware Dynamic Backdoor AttackTuan Anh Nguyen, Anh Tuan TranNeurIPS 2020 · 601 citations
Related papers
- Backdoor Attacks on Bimodal Salient Object Detection with RGB-Thermal DataWen Yin, Bin Benjamin Zhu, Yulai Xie, Pan Zhou et al.ACM MM 2024 · 1 citation
- FRBAT: Conditionally-Visible Physical Backdoor Attack via FluorescenceYalun Wu, Liu Liu, Endong Tong, Yingxiao Xiang et al.AAAI 2026
- MOBA: A Material-Oriented Backdoor Attack Against LiDAR-Based 3D Object Detection SystemsSaket Sanjeev Chaturvedi, Gaurav Bagwe, Lan Emily Zhang, Pan He et al.AAAI 2026
- Backdoor Attacks Against Deep Learning Systems in the Physical WorldEmily Wenger, Josephine Passananti, Arjun Nitin Bhagoji, Yuanshun Yao et al.CVPR 2021
- Dual-Key Multimodal Backdoors for Visual Question AnsweringMatthew Walmer, Karan Sikka, Indranil Sur, Abhinav Shrivastava et al.CVPR 2022 · 27 citations
