Sponge Backdoor Attack: Increasing the Latency of Object Detection Exploiting Non-Maximum Suppression

Yong Xiao,Jin Ma,Ping Yi,Xiuzhen Chen
DOI: https://doi.org/10.1109/ijcnn60899.2024.10650435
2024-01-01
Abstract:Backdoor attacks against deep learning based object detectors have been studied increasingly in recent years. While most proposed attacks primarily focus on compromising the model’s integrity by inducing incorrect detections, only few studies explore backdoor attacks targeting the model’s availability, a critical concern in safety-critical domains such as autonomous driving. In this paper, we introduce a novel backdoor attack called the Sponge Backdoor Attack (SBA), designed to increase the detection latency of end-to-end object detectors. Specifically, we overload a commonly employed technique in many object detectors - non-maximum suppression (NMS) by introducing a large amount of non-existent objects. Through comprehensive experiments, we demonstrate the SBA’s effectiveness to prolong the processing time of the poisoned image while maintaining detection performance on clean images across various models, datasets, and hardware platforms.
What problem does this paper attempt to address?