已入深夜,您辛苦了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!祝你早点完成任务,早点休息,好梦!

Clean-Label Backdoor Attacks on Video Recognition Models

作者
Shihao Zhao,Xingjun Ma,Xiang Zheng,James A Bailey,Jingjing Chen,Yu–Gang Jiang
出处
期刊:Cornell University - arXiv [Cornell University]
被引量:17
标识
DOI:10.48550/arxiv.2003.03030
摘要

Deep neural networks (DNNs) are vulnerable to backdoor attacks which can hide backdoor triggers in DNNs by poisoning training data. A backdoored model behaves normally on clean test images, yet consistently predicts a particular target class for any test examples that contain the trigger pattern. As such, backdoor attacks are hard to detect, and have raised severe security concerns in real-world applications. Thus far, backdoor research has mostly been conducted in the image domain with image classification models. In this paper, we show that existing image backdoor attacks are far less effective on videos, and outline 4 strict conditions where existing attacks are likely to fail: 1) scenarios with more input dimensions (eg. videos), 2) scenarios with high resolution, 3) scenarios with a large number of classes and few examples per class (a "sparse dataset"), and 4) attacks with access to correct labels (eg. clean-label attacks). We propose the use of a universal adversarial trigger as the backdoor trigger to attack video recognition models, a situation where backdoor attacks are likely to be challenged by the above 4 strict conditions. We show on benchmark video datasets that our proposed backdoor attack can manipulate state-of-the-art video models with high success rates by poisoning only a small proportion of training data (without changing the labels). We also show that our proposed backdoor attack is resistant to state-of-the-art backdoor defense/detection methods, and can even be applied to improve image backdoor attacks. Our proposed video backdoor attack not only serves as a strong baseline for improving the robustness of video models, but also provides a new perspective for more understanding more powerful backdoor attacks.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
画船听雨眠完成签到,获得积分10
1秒前
Orange的应助被内向的朝雪采纳,获得10
1秒前
秋风的应助被张磊采纳,获得10
1秒前
3秒前
5秒前
慕青的应助被嘉樨采纳,获得10
8秒前
充电宝的应助被嘉樨采纳,获得10
8秒前
852的应助被嘉樨采纳,获得10
9秒前
9秒前
FashionBoy的应助被嘉樨采纳,获得10
9秒前
大模型的应助被嘉樨采纳,获得10
9秒前
领导范儿的应助被嘉樨采纳,获得10
9秒前
香蕉觅云的应助被嘉樨采纳,获得10
9秒前
Jasper的应助被嘉樨采纳,获得10
9秒前
Xielin发布了新的文献求助10
10秒前
10秒前
梅子酒发布了新的文献求助10
11秒前
积极凌旋的应助被无解肥采纳,获得10
11秒前
可爱的函函的应助被沉静念烟采纳,获得10
12秒前
坚定小蜜蜂完成签到 ,获得积分10
12秒前
wch完成签到 ,获得积分10
14秒前
想学完成签到,获得积分10
14秒前
夺爱发布了新的文献求助10
16秒前
喵喵发布了新的文献求助10
16秒前
小糯米团完成签到,获得积分10
19秒前
20秒前
20秒前
msy完成签到 ,获得积分10
20秒前
20秒前
21秒前
花花完成签到 ,获得积分10
22秒前
祝余发布了新的文献求助10
23秒前
顾矜的应助被lyyyyyyyyyy采纳,获得30
25秒前
嘟嘟52edm完成签到 ,获得积分10
25秒前
musiuuu发布了新的文献求助10
25秒前
26秒前
Lawrence发布了新的文献求助10
26秒前
万能图书馆的应助被花花采纳,获得10
26秒前
27秒前
外向初蓝完成签到,获得积分10
27秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Aspects of Post-SPE Phonology 2000
CODESSA 2000
Rosenblum, Global Change Biology 800
Berberine regulates the TLR4 signaling pathway to suppress hypoxia-induced proliferation and migration of pulmonary arterial smooth muscle cells 520
Organizational Behavior 510
The Welfare Assembly Line: Public Servants in the Suffering City 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 计算机科学 工程类 纳米技术 有机化学 化学工程 内科学 物理 生物化学 复合材料 催化作用 细胞生物学 人工智能 心理学 无机化学 基因 遗传学
热门帖子
关注 科研通微信公众号,转发送积分 7852727
求助须知:如何正确求助?哪些是违规求助? 9371903
关于积分的说明 20680328
捐赠科研通 7450331
什么是DOI,文献DOI怎么找? 3344437
关于科研通互助平台的介绍 2487070
邀请新用户注册赠送积分活动 2367526