PBIM: Paired Backdoor Injection Method for Change Detection

Rui Huang,Mengjia Hao,Zongyu Guo,Yifan Zhang
DOI: https://doi.org/10.1007/978-981-97-5588-2_28
2024-01-01
Abstract:Recent studies on backdoor attack have demonstrated that classification, object detection, and segmentation models are vulnerable when facing malicious attacks. However, the destructiveness of backdoor attack has not been explored in change detection task that aims to detect the changes from a pair of images captured at different times. In this paper, we try to poison different change detectors. The target is to make the change detector predict a Null map for the poisoned image pair and generate correct result for normal image pair. Unlike image classification having single input, change detection has two images as input. According to this characteristic, we design a paired backdoor injection method, injecting triggers into two images. We conduct extensive experiments on LEVIR-CD dataset with six state-of-the-art change detectors with the proposed trigger injection strategy. Our study can help researchers improve the robustness and safety of change detection models.
What problem does this paper attempt to address?