Nanjing University of Aeronautics and Astronautics Shenzhen Research Institute
被引用0|浏览31
摘要
The extensive adoption of Self-supervised learning (SSL) has led to an increased security threat from backdoor attacks. While existing research has mainly focused on backdoor attacks in image classification, there has been limited exploration of their implications for object detection. Object detection plays a critical role in security-sensitive applications, such as autonomous driving, where backdoor attacks seriously threaten human life and property. In this work, we propose the first backdoor attack designed for object detection tasks in SSL scenarios, called Object Transform Attack (SSL-OTA). SSL-OTA employs a trigger capable of altering predictions of the target object to the desired category, encompassing two attacks: Naive Attack (NA) and Dual-Source Blending Attack (DSBA). NA conducts data poisoning during downstream fine-tuning of the object detector, while DSBA innovatively poisons both the pre-trained encoder (via a shadow dataset) and a minimal subset of the downstream data. Notably, using Faster R-CNN on the PASCAL VOC2007 dataset, our NA achieved an Attack Success Rate (ASR) of 72.56%, while our DSBA reached an ASR of 86.55%. Both results were achieved at an extremely low poisoning rate of 0.5%, and the resulting performance impact on the benign mean Average Precision (mAP) was less than 1%. The results underscore the importance of considering backdoor threats in SSL-based object detection and contribute a novel perspective to the field.