arXiv:2603.13864cs.CRcs.CV2026-03

图像压缩会破坏后门触发器,新方法让攻击在压缩后仍有效

Inevitable Encounters: Backdoor Attacks Involving Lossy Compression

  • 利用区域感兴趣编码机制,动态生成触发掩码
  • 在JPEG和学习型压缩下均实现90%以上攻击成功率
  • 适合研究数据安全与对抗样本防御的学者

真实世界中的后门攻击常需存储和传输被污染的数据集。然而,在大数据时代,不可避免的有损压缩会对隐形后门攻击构成根本挑战。我们发现,嵌入到RGB图像中的触发器在经有损压缩为二进制比特流(如JPEG文件)后往往失效,导致污染数据失去恶意作用,使后门注入失败。本文强调必须显式考虑有损压缩过程对后门攻击的影响。攻击者需确保传输的二进制比特流保留恶意触发信息,以在解压后恢复有效触发器。基于图像压缩中的区域感兴趣(ROI)编码机制,我们提出两种针对不可避免有损压缩的中毒策略:一是通用攻击激活(Universal Attack Activation),使用样本特定的ROI掩码在学习型图像压缩(LIC)中重激活触发信息;二是压缩自适应攻击(Compression-Adapted Attack),采用定制化ROI掩码将触发信息编码至比特流,适用于传统编码器和LIC。大量实验验证了两种策略的有效性。

原文摘要 · Abstract (English)

Real-world backdoor attacks often require poisoned datasets to be stored and transmitted before being used to compromise deep learning systems. However, in the era of big data, the inevitable use of lossy compression poses a fundamental challenge to invisible backdoor attacks. We find that triggers embedded in RGB images often become ineffective after the images are lossily compressed into binary bitstreams (e.g., JPEG files) for storage and transmission. As a result, the poisoned data lose its malicious effect after compression, causing backdoor injection to fail. In this paper, we highlight the necessity of explicitly accounting for the lossy compression process in backdoor attacks. This requires attackers to ensure that the transmitted binary bitstreams preserve malicious trigger information, so that effective triggers can be recovered in the decompressed data. Building on the region-of-interest (ROI) coding mechanism in image compression, we propose two poisoning strategies tailored to inevitable lossy compression. First, we introduce Universal Attack Activation, a universal method that uses sample-specific ROI masks to reactivate trigger information in binary bitstreams for learned image compression (LIC). Second, we present Compression-Adapted Attack, a new attack strategy that employs customized ROI masks to encode trigger information into binary bitstreams and is applicable to both traditional codecs and LIC. Extensive experiments demonstrate the effectiveness of both strategies.

后门攻击图像压缩对抗样本安全防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。