Backdoor Attacks Against Deep Image Compression via Adaptive Frequency Trigger

被引:14
作者
Yu, Yi [1 ,3 ]
Wang, Yufei
Yang, Wenhan [2 ]
Lu, Shijian [1 ]
Tan, Yap-Peng [1 ]
Kot, Alex C. [1 ]
机构
[1] Nanyang Technol Univ, Singapore, Singapore
[2] Peng Cheng Lab, Shenzhen, Peoples R China
[3] Nanyang Technol Univ, IGP ROSE, Singapore, Singapore
来源
2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR) | 2023年
关键词
D O I
10.1109/CVPR52729.2023.01179
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Recent deep-learning-based compression methods have achieved superior performance compared with traditional approaches. However, deep learning models have proven to be vulnerable to backdoor attacks, where some specific trigger patterns added to the input can lead to malicious behavior of the models. In this paper, we present a novel backdoor attack with multiple triggers against learned image compression models. Motivated by the widely used discrete cosine transform (DCT) in existing compression systems and standards, we propose a frequency-based trigger injection model that adds triggers in the DCT domain. In particular, we design several attack objectives for various attacking scenarios, including: 1) attacking compression quality in terms of bit-rate and reconstruction quality; 2) attacking task-driven measures, such as down-stream face recognition and semantic segmentation. Moreover, a novel simple dynamic loss is designed to balance the influence of different loss terms adaptively, which helps achieve more efficient training. Extensive experiments show that with our trained trigger injection models and simple modification of encoder parameters (of the compression model), the proposed attack can successfully inject several backdoors with corresponding triggers in a single image compression model.
引用
收藏
页码:12250 / 12259
页数:10
相关论文
共 58 条
[1]  
Al Kader Hammoud Hasan Abed, 2022, BRIT MACH VIS C
[2]  
[Anonymous], 2021, P IEEE CVF C COMP VI, DOI DOI 10.1109/TPAMI.2020.2970919
[3]  
Balle J., 2016, PICT COD SYMP, P1, DOI DOI 10.1109/PCS.2016.7906310
[4]  
Balle J, 2018, INT C LEARN REPR
[5]   End-to-End Learnt Image Compression via Non-Local Attention Optimization and Improved Context Modeling [J].
Chen, Tong ;
Liu, Haojie ;
Ma, Zhan ;
Shen, Qiu ;
Cao, Xun ;
Wang, Yao .
IEEE TRANSACTIONS ON IMAGE PROCESSING, 2021, 30 :3179-3191
[6]  
Chen X., 2021, ICML 2021 WORKSH ADV
[7]  
Chen Xinyun, 2017, ARXIV171205526
[8]   The OGF-OGFr axis utilizes the p21 pathway to restrict progression of human pancreatic cancer [J].
Cheng, Fan ;
McLaughlin, Patricia J. ;
Verderame, Michael F. ;
Zagon, Ian S. .
MOLECULAR CANCER, 2008, 7 (1)
[9]   The Cityscapes Dataset for Semantic Urban Scene Understanding [J].
Cordts, Marius ;
Omran, Mohamed ;
Ramos, Sebastian ;
Rehfeld, Timo ;
Enzweiler, Markus ;
Benenson, Rodrigo ;
Franke, Uwe ;
Roth, Stefan ;
Schiele, Bernt .
2016 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2016, :3213-3223
[10]  
Deng J, 2009, PROC CVPR IEEE, P248, DOI 10.1109/CVPRW.2009.5206848