B³A: Bokeh Based Backdoor Attack with Feature Restrictions

Junjian Li,Honglong Chen,Yudong Gao,Kai Lin,Yuping Liu
DOI: https://doi.org/10.1109/msn60784.2023.00099
2023-01-01
Abstract:Deep neural networks (DNNs) are gradually becoming the preference for the various vision applications of smart cities. However, their success heavily relies on the access to extensive training data and substantial computational resources, posing challenges in training large-scale models for diverse smart city applications. Consequently, the third-party services and resources are often utilized to train the models, exposing them to the potential backdoor attacks. Despite the escalating threat of such attacks, many existing strategies primarily focus on enhancing the stealthiness and evading defenses, often neglecting practical feasibility in the real-world scenarios. In this paper, we introduce a novel backdoor attack named bokeh based backdoor attack $(B^{3}A)$, which leverages the bokeh effect as the trigger. Once the backdoor is deployed in a vision application model, the model’s malicious behavior can be activated solely by using the captured bokeh images. Specifically, we employ saliency and depth estimation maps to synthesize the bokeh images, effectively serving as the poisoned samples. Moreover, we devise a reference model to impose constraints on the feature representations of the poisoned images, thereby further enhancing their stealthiness in the feature space. Extensive experiments demonstrate the attack effects of $B^{3}A$, even on the bokeh photos taken from Digital Still Cameras (DSC) and smartphones.
What problem does this paper attempt to address?