Backdoor Attacks Against Deep Image Compression via Adaptive Frequency Trigger

02/28/2023
by   Yi Yu, et al.
0

Recent deep-learning-based compression methods have achieved superior performance compared with traditional approaches. However, deep learning models have proven to be vulnerable to backdoor attacks, where some specific trigger patterns added to the input can lead to malicious behavior of the models. In this paper, we present a novel backdoor attack with multiple triggers against learned image compression models. Motivated by the widely used discrete cosine transform (DCT) in existing compression systems and standards, we propose a frequency-based trigger injection model that adds triggers in the DCT domain. In particular, we design several attack objectives for various attacking scenarios, including: 1) attacking compression quality in terms of bit-rate and reconstruction quality; 2) attacking task-driven measures, such as down-stream face recognition and semantic segmentation. Moreover, a novel simple dynamic loss is designed to balance the influence of different loss terms adaptively, which helps achieve more efficient training. Extensive experiments show that with our trained trigger injection models and simple modification of encoder parameters (of the compression model), the proposed attack can successfully inject several backdoors with corresponding triggers in a single image compression model.

READ FULL TEXT

page 1

page 4

page 5

page 6

page 7

page 8

research
01/03/2022

Compression-Resistant Backdoor Attack against Deep Neural Networks

In recent years, many backdoor attacks based on training data poisoning ...
research
02/01/2022

Recognition-Aware Learned Image Compression

Learned image compression methods generally optimize a rate-distortion l...
research
06/08/2018

DSSLIC: Deep Semantic Segmentation-based Layered Image Compression

Deep learning has revolutionized many computer vision fields in the last...
research
08/30/2018

Backdoor Embedding in Convolutional Neural Network Models via Invisible Perturbation

Deep learning models have consistently outperformed traditional machine ...
research
03/18/2022

Adversarial Attacks on Deep Learning-based Video Compression and Classification Systems

Video compression plays a crucial role in enabling video streaming and c...
research
03/28/2022

Differentiable Microscopy for Content and Task Aware Compressive Fluorescence Imaging

The trade-off between throughput and image quality is an inherent challe...
research
01/18/2019

Robust Watermarking of Neural Network with Exponential Weighting

Deep learning has been achieving top performance in many tasks. Since tr...

Please sign up or login with your details

Forgot password? Click here to reset