arXiv:2601.21066cs.CVcs.CR2026-01被引 2

提出新型后门攻击框架,提升目标检测的隐蔽性和物理世界攻击效果。

BadDet+: Robust Backdoor Attacks for Object Detection

  • 采用基于对数屏障的惩罚机制,统一区域误分类与物体消失攻击。
  • 在真实场景中实现优于现有方法的合成到物理迁移效果。
  • 适用于研究检测模型安全性的研究人员,尤其关注对抗性攻击者。

后门攻击对深度学习构成严重威胁,但其在目标检测中的影响仍远不如图像分类明确。尽管已有相关攻击方法,我们发现现有检测类方法存在关键缺陷:依赖不切实际的假设且缺乏物理验证。为此,我们提出 BadDet+,一种基于惩罚项的框架,统一了区域误分类攻击(RMA)与物体消失攻击(ODA)。核心机制采用对数屏障惩罚,抑制触发输入的真实类别预测,在保持干净性能的同时,实现位置与尺度不变性,并显著增强物理鲁棒性。在真实世界基准测试中,BadDet+ 在合成到物理迁移方面优于现有 RMA 与 ODA 基线。理论分析表明,该惩罚作用于特定触发的特征子空间,可稳定诱导攻击而不损害正常推理。这些结果揭示了目标检测系统中的重大漏洞,凸显了专用防御机制的必要性。

原文摘要 · Abstract (English)

Backdoor attacks pose a severe threat to deep learning, yet their impact on object detection remains poorly understood compared to image classification. While attacks have been proposed, we identify critical weaknesses in existing detection-based methods, specifically their reliance on unrealistic assumptions and a lack of physical validation. To bridge this gap, we introduce BadDet+, a penalty-based framework that unifies Region Misclassification Attacks (RMA) and Object Disappearance Attacks (ODA). The core mechanism utilizes a log-barrier penalty to suppress true-class predictions for triggered inputs, resulting in (i) position and scale invariance, and (ii) enhanced physical robustness. On real-world benchmarks, BadDet+ achieves superior synthetic-to-physical transfer compared to existing RMA and ODA baselines while preserving clean performance. Theoretical analysis confirms the proposed penalty acts within a trigger-specific feature subspace, reliably inducing attacks without degrading standard inference. These results highlight significant vulnerabilities in object detection and the necessity for specialized defenses.

后门攻击目标检测安全防御物理攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。