arXiv:2502.20306cs.CV2025-02被引 3

首个防御注视估计模型后门攻击的方案,保障人机交互安全。

SecureGaze: Defending Gaze Estimation Against Backdoor Attacks

  • 通过逆向工程识别后门触发函数,定位异常注视偏差
  • 在数字与物理场景下均有效检测多种后门攻击
  • 专为连续输出的注视估计设计,适合车载监控等高危场景

注视估计模型广泛应用于驾驶员注意力监测和人机交互。现有方法依赖数据密集型深度学习,常需使用未经验证的公开数据集、外包训练或依赖预训练模型,易受后门攻击。攻击者通过污染训练数据注入触发器,使模型在正常输入下表现正常,但一旦出现特定触发器便产生被操控的注视方向,威胁驾驶安全等应用。目前尚无针对注视估计的后门防御方案。为此,我们提出SecureGaze——首个专为注视估计设计的防御机制。不同于分类模型,注视估计具有连续输出空间和全局激活的后门行为,我们基于其独特特征,提出新型触发函数逆向方法,实现可靠检测。在数字与物理世界中的大量实验表明,SecureGaze能有效应对多种后门攻击,性能优于七种从分类模型迁移的先进防御方法。

原文摘要 · Abstract (English)

Gaze estimation models are widely used in applications such as driver attention monitoring and human-computer interaction. While many methods for gaze estimation exist, they rely heavily on data-hungry deep learning to achieve high performance. This reliance often forces practitioners to harvest training data from unverified public datasets, outsource model training, or rely on pre-trained models. However, such practices expose gaze estimation models to backdoor attacks. In such attacks, adversaries inject backdoor triggers by poisoning the training data, creating a backdoor vulnerability: the model performs normally with benign inputs, but produces manipulated gaze directions when a specific trigger is present. This compromises the security of many gaze-based applications, such as causing the model to fail in tracking the driver's attention. To date, there is no defense that addresses backdoor attacks on gaze estimation models. In response, we introduce SecureGaze, the first solution designed to protect gaze estimation models from such attacks. Unlike classification models, defending gaze estimation poses unique challenges due to its continuous output space and globally activated backdoor behavior. By identifying distinctive characteristics of backdoored gaze estimation models, we develop a novel and effective approach to reverse-engineer the trigger function for reliable backdoor detection. Extensive evaluations in both digital and physical worlds demonstrate that SecureGaze effectively counters a range of backdoor attacks and outperforms seven state-of-the-art defenses adapted from classification models.

注视估计后门攻击安全防御模型鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。