arXiv:2502.20943cs.CVeess.IV2025-02被引 8

提出针对参考图像超分的后门攻击,让模型在特定触发下输出指定图像。

BadRefSR: Backdoor Attacks Against Reference-based Image Super Resolution

  • 通过向参考图像添加触发器并混合损失训练,实现后门植入。
  • 模型对正常输入表现正常,触发后输出攻击者指定目标图像。
  • 揭示了参考超分模型潜在安全风险,适合关注AI安全的研究者。

参考图像超分辨率(RefSR)是超分辨率技术的重要进展,相比单图超分(SISR),利用额外参考图像恢复高频细节。然而,其对后门攻击的脆弱性尚未被研究。为此,本文提出新型攻击框架BadRefSR,通过在参考图像中添加触发器,并采用混合损失函数进行训练,实现后门植入。大量实验表明,受攻击的RefSR网络在干净输入下表现正常,而在触发输入下输出攻击者指定的目标图像。本研究旨在警示研究人员注意RefSR中的潜在后门风险。代码已公开于https://github.com/xuefusiji/BadRefSR。

原文摘要 · Abstract (English)

Reference-based image super-resolution (RefSR) represents a promising advancement in super-resolution (SR). In contrast to single-image super-resolution (SISR), RefSR leverages an additional reference image to help recover high-frequency details, yet its vulnerability to backdoor attacks has not been explored. To fill this research gap, we propose a novel attack framework called BadRefSR, which embeds backdoors in the RefSR model by adding triggers to the reference images and training with a mixed loss function. Extensive experiments across various backdoor attack settings demonstrate the effectiveness of BadRefSR. The compromised RefSR network performs normally on clean input images, while outputting attacker-specified target images on triggered input images. Our study aims to alert researchers to the potential backdoor risks in RefSR. Codes are available at https://github.com/xuefusiji/BadRefSR.

后门攻击图像超分AI安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。