Backdoor Attacks Against Deep Image Compression via Adaptive Frequency Trigger
Yi Yu, Yufei Wang, Wenhan Yang, Shijian Lu, Yap-Peng Tan, Alex C. Kot
摘要
Recent deep-learning-based compression methods have achieved superior performance compared with traditional approaches. However, deep learning models have proven to be vulnerable to backdoor attacks, where some specific trigger patterns added to the input can lead to malicious behavior of the models. In this paper, we present a novel backdoor attack with multiple triggers against learned image compression models. Motivated by the widely used discrete cosine transform (DCT) in existing compression systems and standards, we propose a frequency-based trigger injection model that adds triggers in the DCT domain. In particular, we design several attack objectives for various attacking scenarios, including: 1) attacking compression quality in terms of bit-rate and reconstruction quality; 2) attacking task-driven measures, such as down-stream face recognition and semantic segmentation. Moreover, a novel simple dynamic loss is designed to balance the influence of different loss terms adaptively, which helps achieve more efficient training. Extensive experiments show that with our trained trigger injection models and simple modification of encoder parameters (of the compression model), the proposed attack can successfully inject several backdoors with corresponding triggers in a single image compression model.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- Frequency Guidance Matters in Few-Shot LearningHao Cheng, Siyuan Yang, Joey Tianyi Zhou, Lanqing Guo 等ICCV 2023 · 被引用 48 次
- Transferable Adversarial Attacks on SAM and Its Downstream ModelsSong Xia, Wenhan Yang, Yi Yu, Xun Lin 等NeurIPS 2024 · 被引用 29 次
- Purify Unlearnable Examples via Rate-Constrained Variational AutoencodersYi Yu, Yufei Wang, Song Xia, Wenhan Yang 等ICML 2024 · 被引用 22 次
- Mitigating the Curse of Dimensionality for Certified Robustness via Dual Randomized SmoothingSong Xia, Yi Yu, Xudong Jiang, Henghui DingICLR 2024 · 被引用 18 次
- Backdoor Attacks Against No-Reference Image Quality Assessment Models via a Scalable TriggerYi Yu, Song Xia, Xun Lin, Wenhan Yang 等AAAI 2025 · 被引用 15 次
它引用的顶会 Paper16
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 被引用 1,633 次
- Invisible Backdoor Attack with Sample-Specific TriggersYuezun Li, Yiming Li, Baoyuan Wu, Longkang Li 等ICCV 2021 · 被引用 639 次
- Input-Aware Dynamic Backdoor AttackTuan Anh Nguyen, Anh Tuan TranNeurIPS 2020 · 被引用 601 次
- Low-Light Image Enhancement with Normalizing FlowYufei Wang, Renjie Wan, Wenhan Yang, Haoliang Li 等AAAI 2022 · 被引用 548 次
- LIRA: Learnable, Imperceptible and Robust Backdoor AttacksKhoa D. Doan, Yingjie Lao, Weijie Zhao, Ping LiICCV 2021 · 被引用 313 次
相关 Paper
- Conditional Backdoor Attack via JPEG CompressionQiuyu Duan, Zhongyun Hua, Qing Liao, Yushu Zhang 等AAAI 2024 · 被引用 21 次
- A Dual Stealthy Backdoor: From Both Spatial and Frequency PerspectivesYudong Gao, Honglong Chen, Peng Sun, Junjian Li 等AAAI 2024 · 被引用 30 次
- Revisiting Backdoor Attacks on Time Series Classification in the Frequency DomainYuanmin Huang, Mi Zhang, Zhaoxiang Wang, Wenxuan Li 等WWW 2025 · 被引用 5 次
- Inaudible Backdoor Attack via Stealthy Frequency Trigger Injection in Audio SpectrogramTianfang Zhang, Huy Phan, Zijie Tang, Cong Shi 等MobiCom 2024 · 被引用 8 次
- Rethinking the Backdoor Attacks' Triggers: A Frequency PerspectiveYi Zeng, Won Park, Z. Morley Mao, Ruoxi JiaICCV 2021 · 被引用 274 次
