Backdoor Attacks on Crowd Counting
Yuhua Sun, Tailai Zhang, Xingjun Ma, Pan Zhou, Jian Lou, Zichuan Xu, Xing Di, Yu Cheng, Lichao Sun
摘要
Crowd counting is a regression task that estimates the number of people in a scene image, which plays a vital role in a range of safety-critical applications, such as video surveillance, traffic monitoring and flow control. In this paper, we investigate the vulnerability of deep learning based crowd counting models to backdoor attacks, a major security threat to deep learning. A backdoor attack implants a backdoor trigger into a target model via data poisoning so as to control the model's predictions at test time. Different from image classification models on which most of existing backdoor attacks have been developed and tested, crowd counting models are regression models that output multi-dimensional density maps, thus requiring different techniques to manipulate. In this paper, we propose two novel Density Manipulation Backdoor Attacks (DMBA- and DMBA+) to attack the model to produce arbitrarily large or small density estimations. Experimental results demonstrate the effectiveness of our DMBA attacks on five classic crowd counting models and four types of datasets. We also provide an in-depth analysis of the unique challenges of backdooring crowd counting models and reveal two key elements of effective attacks: 1) full and dense triggers and 2) manipulation of the ground truth counts or density maps. Our work could help evaluate the vulnerability of crowd counting models to potential backdoor attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Physical Backdoor: Towards Temperature-Based Backdoor Attacks in the Physical WorldWen Yin, Jian Lou, Pan Zhou, Yulai Xie 等CVPR 2024 · 被引用 9 次
- Distilling Cognitive Backdoor Patterns within an ImageHanxun Huang, Xingjun Ma, Sarah Monazam Erfani, James BaileyICLR 2023 · 被引用 7 次
- BadToken: Token-level Backdoor Attacks to Multi-modal Large Language ModelsZenghui Yuan, Jiawen Shi, Pan Zhou, Neil Zhenqiang Gong 等CVPR 2025
- Backdoor Cleansing with Unlabeled DataLu Pang, Tao Sun, Haibin Ling, Chao ChenCVPR 2023
- You Are Catching My Attention: Are Vision Transformers Bad Learners under Backdoor Attacks?Zenghui Yuan, Pan Zhou, Kai Zou, Yu ChengCVPR 2023
它引用的顶会 Paper24
- DBA: Distributed Backdoor Attacks against Federated LearningChulin Xie, Keli Huang, Pin-Yu Chen, Bo LiICLR 2020 · 被引用 901 次
- Improving Adversarial Robustness Requires Revisiting Misclassified ExamplesYisen Wang, Difan Zou, Jinfeng Yi, James Bailey 等ICLR 2020 · 被引用 829 次
- Hidden Trigger Backdoor AttacksAniruddha Saha, Akshayvarun Subramanya, Hamed PirsiavashAAAI 2020 · 被引用 743 次
- Bayesian Loss for Crowd Count Estimation With Point SupervisionZhiheng Ma, Xing Wei, Xiaopeng Hong, Yihong GongICCV 2019 · 被引用 612 次
- Input-Aware Dynamic Backdoor AttackTuan Anh Nguyen, Anh Tuan TranNeurIPS 2020 · 被引用 601 次
相关 Paper
- Towards Adversarial Patch Analysis and Certified Defense against Crowd CountingQiming Wu, Zhikang Zou, Pan Zhou, Xiaoqing Ye 等ACM MM 2021 · 被引用 2 次
- PatchBackdoor: Backdoor Attack against Deep Neural Networks without Model ModificationYizhen Yuan, Rui Kong, Shenghao Xie, Yuanchun Li 等ACM MM 2023 · 被引用 12 次
- PointBA: Towards Backdoor Attacks in 3D Point CloudXinke Li, Zhirui Chen, Yue Zhao, Zekun Tong 等ICCV 2021 · 被引用 62 次
- AEVA: Black-box Backdoor Detection Using Adversarial Extreme Value AnalysisJunfeng Guo, Ang Li, Cong LiuICLR 2022 · 被引用 92 次
- Clean-Label Physical Backdoor Attacks with Data DistillationThinh Dao, Khoa D. Doan, Kok-Seng WongAAAI 2026 · 被引用 3 次
