Built independently by an author, for readers. Read the story and support ChapterPal

keyword

pixel-wise ASR

Pixel-wise attack success rate is an evaluation metric in adversarial machine learning that measures the proportion of individual pixels in an image that are successfully manipulated to achieve an attacker objective when a perturbation or backdoor trigger is activated. Unlike standard attack success rates that evaluate whole-image predictions as binary outcomes, this metric provides a granular measurement suited for dense computer vision and image processing tasks, such as semantic segmentation and learned image compression. In these settings, it quantifies attack efficacy across spatial dimensions by calculating the percentage of pixels that are driven to an intended target label, altered in reconstruction quality, or corrupted during downstream task execution.

1 item

Backdoor Attacks Against Deep Image Compression via Adaptive Frequency Trigger

Backdoor Attacks Against Deep Image Compression via Adaptive Frequency Trigger

Yi Yu, Yufei Wang, Wenhan Yang, Shijian Lu, Yap-Peng Tan, Alex C. Kot

OrganizationsNanyang Technological UniversityPeng Cheng Laboratory

Why you should read this

Presents a frequency-based backdoor attack targeting deep image compression models by injecting adaptive discrete cosine transform triggers into only the encoder, effectively compromising reconstruction quality, bit-rate, and downstream vision tasks without altering the decoder.

Recent deep-learning-based compression methods have achieved superior performance compared with traditional approaches. However, deep learning models have proven to be vulnerable to backdoor attacks, where some specific trigger patterns added to the input can lead to malicious behavior of the models. In this paper, we present a novel backdoor attack with multiple triggers against learned image compression models. Motivated by the widely used discrete cosine transform (DCT) in existing compression systems and standards, we propose a frequency-based trigger injection model that adds triggers in the DCT domain. In particular, we design several attack objectives for various attacking scenarios, including: 1) attacking compression quality in terms of bit-rate and reconstruction quality; 2) attacking task-driven measures, such as down-stream face recognition and semantic segmentation. Moreover, a novel simple dynamic loss is designed to balance the influence of different loss terms adaptively, which helps achieve more efficient training. Extensive experiments show that with our trained trigger injection models and simple modification of encoder parameters (of the compression model), the proposed attack can successfully inject several backdoors with corresponding triggers in a single image compression model.

Added

2026-09-26