arrow
返回

Stealthy Targeted Backdoor Attacks Against Image Captioning

delete2024-01-01
delete0
delete
OA
AI
W
Wenshu Fan
H
Hongwei Li
W
Wenbo Jiang *
M
Meng Hao
S
Shui Yu
X
Xiao Zhang
DOI:10.1109/TIFS.2024.3402179delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
In recent years, there is an explosive growth in multimodal learning. Image captioning, a classical multimodal task, has demonstrated promising applications and attracted extensive research attention. However, recent studies have shown that image caption models are vulnerable to some security threats such as backdoor attacks. Existing backdoor attacks against image captioning typically pair a trigger either with a predefined sentence or a single word as the targeted output, yet they are unrelated to the image content, making them easily noticeable as anomalies by humans. In this paper, we present a novel method to craft targeted backdoor attacks against image caption models, which are designed to be stealthier than prior attacks. Specifically, our method first learns a special trigger by leveraging universal perturbation techniques for object detection, then places the learned trigger in the center of some specific source object and modifies the corresponding object name in the output caption to a predefined target name. During the prediction phase, the caption produced by the backdoored model for input images with the trigger can accurately convey the semantic information of the rest of the whole image, while incorrectly recognizing the source object as the predefined target. Extensive experiments demonstrate that our approach can achieve a high attack success rate while having a negligible impact on model clean performance. In addition, we show our method is stealthy in that the produced backdoor samples are indistinguishable from clean samples in both image and text domains, which can successfully bypass existing backdoor defenses, highlighting the need for better defensive mechanisms against such stealthy backdoor attacks.
Keyword:
Perturbation methods
Detectors
Task analysis
Predictive models
Biological system modeling
Electronic mail
Data models
Backdoor attack
image caption
deep learning

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.3K
被引数:
2.3W

机构

U
university of technology sydney
学者数:
1.6W
论文数: 2.0W
被引数: 25
引用论文

引用论文

err分享
err收藏
Distribution of telomeric (TTAGGG)n sequences in avian chromosomes
err2002-11-01
err0
PREAI
errIndrajit Nanda; David Schrama; Wolfgang Feichtinger; Thomas Haaf; Manfred Schartl; Michael Schmid
err分享
err收藏
Deep Hashing for Secure Multimodal Biometrics
err2021-01-01
err50
errOAAI
errTalreja, Veeru; Valenti, Matthew C.; Nasrabadi, Nasser M.
err分享
err收藏
Propiedades psicométricas de una versión breve del Driving Anger Expression Inventory en conductores españoles
err2019-05-28
err0
errOAAI
errDavid Herrero Fernández; Mireia Oliva-Macías; Pamela Parada-Fernández
err分享
err收藏
学者 查看更多内容