arrow
Return

DBBA: Diffusion-Based Backdoor Attacks on Open-Set Face Recognition Models

delete2026-01-01
delete0
PRE
AI
F
Fuqi Qi
H
Haichang Gao *
L
LI Bo-ling
何光宇 (Guangyu He)
张宇虹 cover
张宇虹 (Yuhong Zhang)
J
Jiacheng Luo
DOI:10.1007/978-3-032-07884-1_16delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Deep neural network-based face recognition models are widely deployed in authentication systems but remain vulnerable to backdoor attacks. Existing methods face critical limitations: (1) label-poisoning attacks are easily detectable, while clean-label attacks often rely on adversarial perturbations that degrade image quality; (2) triggers lacking semantic information are conspicuous and impractical in physical settings; and (3) attacker-victim identity selection is often restricted, limiting applicability in open-set scenarios. To address these issues, we propose DBBA, a diffusion-based backdoor attack framework that operates under clean-label constraints in open-set face recognition. DBBA leverages the high-fidelity generative power of diffusion models and their multi-modal capabilities to synthesize visually plausible, semantically meaningful poisoned faces. By incorporating trigger optimization, a multi-objective loss, and an adaptive identity selection strategy, our method achieves a good balance between poisoning success and clean accuracy. Extensive experiments validate the stealth, effectiveness, and real-world applicability of DBBA, which can inspire and promote the security enhancement of the application of face recognition models in the future.
Keywords:
Backdoor attack
Open-set Face recognition
Diffusion model
Clean label

Journal

C
COMPUTER SECURITY-ESORICS 2025, PT I
IF:
0
Papers:
22
Citations:
0

Organization

X
xidian university
Scholars:
5.7K
Papers: 2.0K
Citations: 0