Backdoor Attacks on Crowd Counting
arXiv:2207.05641 · doi:10.1145/3503161.3548296
Abstract
Crowd counting is a regression task that estimates the number of people in a scene image, which plays a vital role in a range of safety-critical applications, such as video surveillance, traffic monitoring and flow control. In this paper, we investigate the vulnerability of deep learning based crowd counting models to backdoor attacks, a major security threat to deep learning. A backdoor attack implants a backdoor trigger into a target model via data poisoning so as to control the model's predictions at test time. Different from image classification models on which most of existing backdoor attacks have been developed and tested, crowd counting models are regression models that output multi-dimensional density maps, thus requiring different techniques to manipulate. In this paper, we propose two novel Density Manipulation Backdoor Attacks (DMBA and DMBA) to attack the model to produce arbitrarily large or small density estimations. Experimental results demonstrate the effectiveness of our DMBA attacks on five classic crowd counting models and four types of datasets. We also provide an in-depth analysis of the unique challenges of backdooring crowd counting models and reveal two key elements of effective attacks: 1) full and dense triggers and 2) manipulation of the ground truth counts or density maps. Our work could help evaluate the vulnerability of crowd counting models to potential backdoor attacks.
To appear in ACMMM 2022. 10pages, 6 figures and 2 tables
References in corpus (11)
- YOLOv4: Optimal Speed and Accuracy of Object Detection
- Explaining and Harnessing Adversarial Examples
- Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning
- On the Convergence and Robustness of Adversarial Training
- Skip Connections Matter: On the Transferability of Adversarial Examples Generated with ResNets
- Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural Networks
- Transferable Clean-Label Poisoning Attacks on Deep Neural Nets
- Dual Path Multi-Scale Fusion Networks with Attention for Crowd Counting
- Backdoor Attack in the Physical World
- Few-Shot Backdoor Attacks on Visual Object Tracking
- Cross-View Cross-Scene Multi-View Crowd Counting