BadSAD对异常检测模型发动隐蔽后门攻击,让恶意样本骗过系统。
BadSAD: Clean-Label Backdoor Attacks against Deep Semi-Supervised Anomaly Detection
- 在正常图像中嵌入微小触发器,伪装成正常数据
- 操控特征空间使中毒样本靠近正常样本,逃避检测
- 针对深度半监督异常检测,适合研究安全性的学者
图像异常检测(IAD)在工业检测、医学影像和安全等领域至关重要。尽管深度学习模型如深度半监督异常检测(DeepSAD)取得了进展,但仍易受后门攻击威胁,带来严重安全隐患。本文提出针对DeepSAD模型的新型后门攻击框架BadSAD,包含两个关键阶段:触发注入,将细微触发器嵌入正常图像;以及潜在空间操控,将中毒图像定位并聚类在正常图像附近,使触发器表现得像正常数据。在基准数据集上的大量实验验证了该攻击策略的有效性,突显了基于深度学习的异常检测系统面临的严峻安全风险。
原文摘要 · Abstract (English)
Image anomaly detection (IAD) is essential in applications such as industrial inspection, medical imaging, and security. Despite the progress achieved with deep learning models like Deep Semi-Supervised Anomaly Detection (DeepSAD), these models remain susceptible to backdoor attacks, presenting significant security challenges. In this paper, we introduce BadSAD, a novel backdoor attack framework specifically designed to target DeepSAD models. Our approach involves two key phases: trigger injection, where subtle triggers are embedded into normal images, and latent space manipulation, which positions and clusters the poisoned images near normal images to make the triggers appear benign. Extensive experiments on benchmark datasets validate the effectiveness of our attack strategy, highlighting the severe risks that backdoor attacks pose to deep learning-based anomaly detection systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。