Influencer Backdoor Attack on Semantic Segmentation

03/21/2023
by   Haoheng Lan, et al.
0

When a small number of poisoned samples are injected into the training dataset of a deep neural network, the network can be induced to exhibit malicious behavior during inferences, which poses potential threats to real-world applications. While they have been intensively studied in classification, backdoor attacks on semantic segmentation have been largely overlooked. Unlike classification, semantic segmentation aims to classify every pixel within a given image. In this work, we explore backdoor attacks on segmentation models to misclassify all pixels of a victim class by injecting a specific trigger on non-victim pixels during inferences, which is dubbed Influencer Backdoor Attack (IBA). IBA is expected to maintain the classification accuracy of non-victim pixels and misleads classifications of all victim pixels in every single inference. Specifically, we consider two types of IBA scenarios, i.e., 1) Free-position IBA: the trigger can be positioned freely except for pixels of the victim class, and 2) Long-distance IBA: the trigger can only be positioned somewhere far from victim pixels, given the possible practical constraint. Based on the context aggregation ability of segmentation models, we propose techniques to improve IBA for the scenarios. Concretely, for free-position IBA, we propose a simple, yet effective Nearest Neighbor trigger injection strategy for poisoned sample creation. For long-distance IBA, we propose a novel Pixel Random Labeling strategy. Our extensive experiments reveal that current segmentation models do suffer from backdoor attacks, and verify that our proposed techniques can further increase attack performance.

READ FULL TEXT

page 1

page 4

page 7

page 13

research
03/06/2021

Hidden Backdoor Attack against Semantic Segmentation Models

Deep neural networks (DNNs) are vulnerable to the backdoor attack, which...
research
03/14/2023

Class-level Multiple Distributions Representation are Necessary for Semantic Segmentation

Existing approaches focus on using class-level features to improve seman...
research
03/23/2022

GOSS: Towards Generalized Open-set Semantic Segmentation

In this paper, we present and study a new image segmentation task, calle...
research
01/05/2022

On the Real-World Adversarial Robustness of Real-Time Semantic Segmentation Models for Autonomous Driving

The existence of real-world adversarial examples (commonly in the form o...
research
02/24/2018

Superpixel based Class-Semantic Texton Occurrences for Natural Roadside Vegetation Segmentation

Vegetation segmentation from roadside data is a field that has received ...
research
03/16/2022

Hyperbolic Uncertainty Aware Semantic Segmentation

Semantic segmentation (SS) aims to classify each pixel into one of the p...
research
11/13/2015

Learning Dense Convolutional Embeddings for Semantic Segmentation

This paper proposes a new deep convolutional neural network (DCNN) archi...

Please sign up or login with your details

Forgot password? Click here to reset