Color Backdoor: A Robust Poisoning Attack in Color Space

Wenbo JiangHongwei LiGuowen XuTianwei Zhang

article2023CVPR107 citations

Proposes a stealthy data poisoning attack that applies an optimized uniform color space shift across image pixels to embed backdoors capable of bypassing mainstream defense mechanisms and image preprocessing transformations.

Listen

Deep learning models are increasingly deployed in security-critical environments such as autonomous driving and facial authentication, yet they remain vulnerable to backdoor attacks where an adversary poisons training data to cause predictable misclassifications during inference. Recent research has focused on stealthy triggers that look natural or imperceptible to human observers, but these methods frequently fail when subjected to standard image preprocessing defenses such as compression or filtering. The article evaluates a novel poisoning mechanism termed color backdoor, demonstrating that a uniform shift across color space can achieve both visual stealthiness and high resilience against existing security countermeasures under realistic black-box assumptions.

To identify effective attack configurations without access to victim model architectures, the study uses Particle Swarm Optimization to search for optimal color space shifts. The optimization balances attack strength—estimated through early training loss on surrogate models—against perceptual naturalness constraints enforced via standard image quality metrics. The resulting technique was evaluated across multiple benchmark image classification datasets, including CIFAR-10, CIFAR-100, GTSRB, and ImageNet, using a low poisoning rate of 5 percent or less.

The findings show that the color backdoor attack achieves misclassification rates exceeding 96 to 99 percent on target classes while maintaining normal accuracy on clean data. Unlike prior invisible and natural backdoor methods, whose attack effectiveness drops sharply under preprocessing defenses (often falling below 50 percent), the color backdoor maintains attack success rates above 85 to 96 percent against DeepSweep, ShrinkPad, and JPEG compression. Furthermore, because the trigger applies a global transformation across the entire image rather than a local patch or localized feature, it reliably bypasses trigger reconstruction, neuron pruning, entropy-based detection, and spectral signature defenses.

These results demonstrate a critical blind spot in current computer vision security practices: existing defenses largely assume backdoors rely on local pixel anomalies or fragile high-frequency perturbations that can be removed with routine image filtering. Simple adaptive countermeasures, such as applying random color shifts during inference or training-time color augmentations, failed to reliably mitigate the threat, frequently degrading normal model accuracy instead. Organizations deploying neural networks must recognize that standard preprocessing and scanning pipelines are insufficient to detect or neutralize global, transformation-based data poisoning.

Organizations should review their data supply chains, strictly auditing third-party training datasets rather than relying solely on post-training or inference-time defenses. While the study provides high confidence regarding standard vision models and datasets under controlled settings, the authors note that evaluation was focused primarily on standard image benchmarks. Security teams and researchers should conduct further evaluations on complex real-world pipelines and develop defensive mechanisms capable of detecting structural and global distribution shifts in poisoned data.

Cover for Color Backdoor: A Robust Poisoning Attack in Color Space

Abstract

Backdoor attacks against neural networks have been intensively investigated, where the adversary compromises the integrity of the victim model, causing it to make wrong predictions for inference samples containing a specific trigger. To make the trigger more imperceptible and human-unnoticeable, a variety of stealthy backdoor attacks have been proposed, some works employ imperceptible perturbations as the backdoor triggers, which restrict the pixel differences of the triggered image and clean image. Some works use special image styles (e.g., reflection, Instagram filter) as the backdoor triggers. However, these attacks sacrifice the robustness, and can be easily defeated by common preprocessing-based defenses.

This paper presents a novel color backdoor attack, which can exhibit robustness and stealthiness at the same time. The key insight of our attack is to apply a uniform color space shift for all pixels as the trigger. This global feature is robust to image transformation operations and the triggered samples maintain natural-looking. To find the optimal trigger, we first define naturalness restrictions through the metrics of PSNR, SSIM and LPIPS. Then we employ the Particle Swarm Optimization (PSO) algorithm to search for the optimal trigger that can achieve high attack effectiveness and robustness while satisfying the restrictions. Extensive experiments demonstrate the superiority of PSO and the robustness of color backdoor against different main-stream backdoor defenses.

Table of Contents

  • 1. Introduction
  • 2. Related Work
  • 2.1. Backdoor Attacks
  • 2.2. Backdoor Defenses
  • 3. Methodology
  • 3.1. Threat Model and Attack Requirements
  • 3.2. Attack Overview
  • 3.3. Defining the Objective Function of PSO
  • 3.4. Enforcing the Naturalness of a Trigger
  • 3.5. Searching Optimal Triggers Through PSO
  • 4. Evaluation
  • 4.1. Experimental Setup
  • 4.2. Effectiveness Evaluation
  • 4.3. Naturalness Evaluation
  • 4.4. Robustness Evaluation
  • 4.4.1 Preprocessing-based Defenses
  • 4.4.2 Other Mainstream Defenses
  • 4.4.3 Adaptive Defenses
  • 5. Conclusion
  • References

Knowls

  1. Knowl 1 — Uniform Color Space Shift as a Backdoor Trigger

    model/method

    Color backdoor embeds a backdoor into deep neural networks by applying a constant, uniform shift across a selected 3D color space to every pixel of an image. For an input image composed of pixels pi=(pi,1,pi,2,pi,3)p_i = (p_{i,1}, p_{i,2}, p_{i,3}) in a three-dimensional color representation (such as RGB, HSV, LAB, YCbCr, XYZ, or LUV), the triggered pixel pi′p'_i is formulated as:

    pi′=pi+t=(pi,1+t1,pi,2+t2,pi,3+t3)p'_i = p_i + t = (p_{i,1} + t_1, p_{i,2} + t_2, p_{i,3} + t_3)

    where t=(t1,t2,t3)∈R3t = (t_1, t_2, t_3) ∈ \mathbb{R}^3 denotes the global color space shift vector. Because the transformation modifies structural color attributes globally across the entire image rather than altering local high-frequency pixel patches, the triggered image preserves semantic shape and object identity while evading visual inspection.

  2. Knowl 2 — Surrogate Model Objective Function for Color Trigger Optimization

    equation

    To evaluate the attack effectiveness of a candidate color space shift vector t=(t1,t2,t3)t = (t_1, t_2, t_3) without training a full victim model from scratch, the backdoor training loss over a semi-trained surrogate neural network fsf_s is measured on the poisoned training dataset DpD_p. The objective function O(t)O(t) is defined as:

    O(t)=Lb=∑x∈DpCE(fs(x+t),yt)O(t) = \mathcal{L}_b = \sum_{x \in D_p} \text{CE}(f_s(x + t), y_t)

    where CE(⋅,⋅)\text{CE}(\cdot, \cdot) denotes the cross-entropy loss function, xx represents an input image, x+tx + t denotes the image with shift tt applied to each pixel in the chosen color space, yty_t is the target attack label, and DpD_p is the subset of poisoned samples. A smaller backdoor training loss indicates that the trigger is easier for the surrogate model to learn, corresponding to higher attack effectiveness.

  3. Knowl 3 — Naturalness Restrictions and Penalty Formulation for Trigger Optimization

    model/method

    To prevent large color shifts from making triggered images visually unrealistic, naturalness is enforced using Peak Signal-to-Noise Ratio (PSNR), Structural Similarity Index Measure (SSIM), and Learned Perceptual Image Patch Similarity (LPIPS) evaluated over clean and triggered pairs in the poisoned dataset SS. Three penalty terms are defined:

    e1(t)=max⁡(0,λ1−PSNR(t,S))e_1(t) = \max(0, \lambda_1 - \text{PSNR}(t, S))

    e2(t)=max⁡(0,λ2−SSIM(t,S))e_2(t) = \max(0, \lambda_2 - \text{SSIM}(t, S))

    e3(t)=max⁡(0,LPIPS(t,S)−λ3)e_3(t) = \max(0, \text{LPIPS}(t, S) - \lambda_3)

    where λ1,λ2,λ3\lambda_1, \lambda_2, \lambda_3 are similarity threshold hyperparameters. For a swarm of MM candidate triggers {t1,…,tM}\{t_1, \dots, t_M\}, normalized weights wjw_j are computed to balance the penalties into a total penalty P(t)P(t):

    P(t)=∑j=13wjej(t),wj=∑i=1Mej(ti)∑k=13∑i=1Mek(ti)P(t) = \sum_{j=1}^3 w_j e_j(t), \quad w_j = \frac{\sum_{i=1}^M e_j(t_i)}{\sum_{k=1}^3 \sum_{i=1}^M e_k(t_i)}

    The total optimization objective is Ototal(t)=O(t)+P(t)O_{\text{total}}(t) = O(t) + P(t). When comparing two candidate triggers tit_i and tjt_j:

    • If both satisfy the naturalness restrictions (P(ti)=P(tj)=0P(t_i) = P(t_j) = 0), tit_i is superior if Ototal(ti)<Ototal(tj)O_{\text{total}}(t_i) < O_{\text{total}}(t_j).
    • If neither satisfies the restrictions, tit_i is superior if P(ti)<P(tj)P(t_i) < P(t_j).
    • If tit_i satisfies the restrictions while tjt_j violates them, tit_i is superior.
  4. Knowl 4 — Particle Swarm Optimization for Optimal Color Trigger Search

    algorithm

    Particle Swarm Optimization (PSO) is used to find the optimal color shift vector t=(t1,t2,t3)t = (t_1, t_2, t_3) without requiring gradient access to the victim model architecture or training pipeline.

    Input: Acceleration factors c1,c2c_1, c_2, random vectors r1,r2∼U(0,1)3r_1, r_2 \sim U(0, 1)^3, inertia weight ω\omega, maximum iterations TT, swarm size MM
    Output: Optimal backdoor color shift gbestgbest
    for each particle i=1i = 1 to MM do
        Randomly initialize particle position tit_i and velocity viv_i
        Calculate total objective Ototal(ti)=O(ti)+P(ti)O_{\text{total}}(t_i) = O(t_i) + P(t_i)
        pbesti←tipbest_i \leftarrow t_i
    end for
    gbest←arg⁡min⁡tiOtotal(ti)gbest \leftarrow \arg\min_{t_i} O_{\text{total}}(t_i) according to the defined naturalness superiority rules
    for iteration j=1j = 1 to TT do
        for each particle i=1i = 1 to MM do
            vi←ωvi+c1r1⊙(pbesti−ti)+c2r2⊙(gbest−ti)v_i \leftarrow \omega v_i + c_1 r_1 \odot (pbest_i - t_i) + c_2 r_2 \odot (gbest - t_i)
            ti←ti+vit_i \leftarrow t_i + v_i
            Calculate Ototal(ti)O_{\text{total}}(t_i)
            if tit_i is superior to pbestipbest_i under naturalness rules then
                pbesti←tipbest_i \leftarrow t_i
            end if
            if tit_i is superior to gbestgbest under naturalness rules then
                gbest←tigbest \leftarrow t_i
            end if
        end for
    end for
    return gbestgbest

    The symbol ⊙\odot represents element-wise vector multiplication. The output gbestgbest is the 3D color shift vector applied to generate the poisoned dataset.

  5. Knowl 5 — Robustness of Color Backdoor Against Preprocessing Defenses

    data/table

    On CIFAR-10, the Color Backdoor attack retains high Attack Success Rate (ASR) across three state-of-the-art inference-time preprocessing defenses (DeepSweep fine-tuning with data augmentation, ShrinkPad shrinking by 2 pixels with zero padding, and JPEG image compression with 75% quality), outperforming eight baseline attacks.

    Attack No defense DeepSweep ShrinkPad Compression Average
    ACC ASR ACC ASR ACC ASR ACC ASR ASR
    BadNet 89.20 99.98 84.57 54.64 85.74 75.20 81.15 41.56 67.85
    Blend 90.16 96.03 85.98 53.20 86.96 17.25 81.36 16.72 45.80
    Input-aware 94.39 98.79 91.59 42.04 88.07 32.69 81.71 49.72 55.81
    WaNet 91.92 96.14 90.21 45.66 87.81 57.13 84.15 13.05 53.00
    Refool 88.66 92.47 82.65 86.37 85.53 93.51 81.60 44.57 79.23
    L0L_0-norm 87.35 77.63 84.38 19.89 83.18 43.30 80.09 35.06 43.97
    L2L_2-norm 90.19 99.86 85.93 15.73 86.71 12.21 84.15 9.23 34.26
    Filter 89.91 99.14 83.64 85.56 85.90 92.57 82.95 23.16 75.11
    Color Backdoor 89.77 97.55 85.50 87.64 86.15 93.61 81.78 96.89 93.92

    While traditional additive triggers (BadNet, L2L_2-norm) and style-based attacks (Filter, Refool) degrade sharply under JPEG compression (9.23%–44.57%9.23\%\text{--}44.57\% ASR), Color Backdoor retains 96.89%96.89\% ASR under compression and maintains a 93.92%93.92\% average ASR across all preprocessing defenses.

  6. Knowl 6 — Efficacy and Search Efficiency of PSO Against Alternative Optimizers

    data/table

    Comparing Particle Swarm Optimization (PSO) against Genetic Algorithm (GA), Grid-search, and Random selection demonstrates that PSO delivers comparable or higher Attack Success Rate (ASR) with substantially lower computational overhead across benchmark datasets.

    Method CIFAR-10 CIFAR-100 GTSRB ImageNet
    Attack Success Rate (ASR, %)
    PSO 97.55 96.27 99.70 98.16
    GA 95.90 96.41 98.87 99.27
    Grid-search 98.17 98.01 99.24 99.39
    Random 92.02 83.54 91.33 87.09
    Searching Time (Hours)
    PSO 1.79 h 3.71 h 1.81 h 3.79 h
    GA 3.22 h 6.30 h 3.17 h 6.89 h
    Grid-search 5.33 h 10.97 h 5.43 h 11.68 h
    Random – – – –

    PSO reduces trigger search time by approximately 44%–48%44\%\text{--}48\% compared to GA and by 66%–68%66\%\text{--}68\% compared to Grid-search across all four datasets while achieving ASR above 96%96\%.

  7. Knowl 7 — Attack Performance Under Varying Poisoning Rates

    data/table

    The clean test accuracy (ACC, %) and Attack Success Rate (ASR, %) of the Color Backdoor attack (evaluated in LUV color space with the target label set to the first class) across four benchmark datasets under poisoning rates ranging from 3% to 10%:

    Poisoning Rate CIFAR-10 CIFAR-100 GTSRB ImageNet
    ACC ASR ACC ASR ACC ASR ACC ASR
    No attack 90.05 – 66.86 – 93.33 – 71.67 –
    3% 89.93 93.77 66.45 93.25 93.21 95.04 70.28 96.44
    5% 89.77 97.55 65.86 96.27 93.36 99.70 69.11 98.16
    8% 89.45 98.45 65.77 98.51 91.55 99.43 68.75 99.01
    10% 87.61 99.03 64.03 98.84 87.60 99.89 66.53 99.17

    Models used are ResNet-18 for CIFAR-10, VGG16 for GTSRB, ResNet-34 for CIFAR-100, and ResNet-34 for ImageNet. At a 5% poisoning rate, Color Backdoor attains ≥96.27%\ge 96.27\% ASR across all datasets while causing minimal degradation in clean accuracy (<1%<1\% drop on CIFAR-10, CIFAR-100, and GTSRB; 2.56%2.56\% drop on ImageNet).

  8. Knowl 8 — Resistance of Color Backdoor to Mainstream Detection and Mitigation Defenses

    empirical result

    Color Backdoor successfully bypasses five categories of mainstream backdoor defenses due to its global uniform color shift characteristics:

    1. Neural Cleanse: Computes an anomaly score for potential patch triggers; Color Backdoor yields an anomaly score <2< 2 (close to clean models) because the trigger functions as a continuous global color transformation rather than a static localized patch, causing trigger reconstruction to fail.
    2. Grad-CAM: Visual explanations on triggered images highlight the central object region identically to clean images, defeating localization-based defenses that identify localized anomalous trigger patches.
    3. Fine-Pruning: Pruning neurons in the final convolutional layer based on average activation values fails to eliminate the backdoor; the ASR consistently remains higher than clean test accuracy (ACC) as neurons are removed up to the 8%8\% ACC drop stopping threshold.
    4. STRIP: Superimposing clean images onto triggered inputs disrupts the specific global color shift, causing the prediction entropy distribution of superimposed triggered samples to overlap with that of clean samples, making entropy-based detection ineffective.
    5. Spectral Signature: Latent representation correlation scores between clean and triggered samples show no bimodal separation because global color shifts influence most neurons broadly rather than producing isolated outlier directions in top singular vectors.
  9. Knowl 9 — Robustness Against Adaptive In-Training and Inference-Time Defenses

    data/table

    Color backdoor demonstrates resilience against adaptive defenses based on color augmentation and random inference-time shifts.

    When training data is augmented with random hue and saturation shifts within a ±30%\pm 30\% range, the backdoored model maintains high ASR across six color spaces on CIFAR-10 and CIFAR-100:

    Color Space CIFAR-10 CIFAR-100
    ACC (%) ASR (%) ACC (%) ASR (%)
    No attack 90.05 – 66.86 –
    RGB 87.15 86.01 63.79 84.75
    HSV 87.43 81.62 65.04 80.43
    LAB 89.01 93.10 64.41 85.26
    YCbCr 89.81 87.89 65.44 85.94
    XYZ 89.53 96.80 64.87 90.17
    LUV 88.17 91.09 64.59 88.32

    Additionally, applying random per-channel color space shifts in (−0.1,0.1)(-0.1, 0.1) at inference time exhibits unstable mitigation: ASR decreases only when the random vector directly opposes and cancels the specific trigger vector tt; otherwise, the defense is ineffective or further degrades clean accuracy.

Coverage note — Omitted experiments on grayscale image datasets (MNIST, FashionMNIST) and physical-world evaluations mentioned in Section 4.1 as their details were relegated to the paper's appendix.

References

  1. 1.Jonathan Bragg, Arman Cohan, Kyle Lo, and Iz Beltagy. Flex: Unifying evaluation for few-shot nlp. Proceedings of NIPS, 34, 2021. 1
  2. 2.Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526, 2017. 1, 2, 6
  3. 3.Siyuan Cheng, Yingqi Liu, Shiqing Ma, and Xiangyu Zhang. Deep feature space trojan attack of neural networks by controlled detoxification. In Proceedings of AAAI, volume 35, pages 1148–1156, 2021. 1, 2, 3, 6
  4. 4.Dogan Corus, Duc-Cuong Dang, Anton V Eremeev, and Per Kristian Lehre. Level-based analysis of genetic algorithms and other search processes. IEEE Transactions on Evolutionary Computation, 22(5):707–719, 2017. 5
  5. 5.Khoa Doan, Yingjie Lao, and Ping Li. Backdoor attack with imperceptible input and latent modification. In Proceedings of NIPS, volume 34, pages 18944–18957, 2021. 1, 2, 3, 6
  6. 6.Russell Eberhart and James Kennedy. A new optimizer using particle swarm theory. In MHS'95. Proceedings of the Sixth International Symposium on Micro Machine and Human Science, pages 39–43. Ieee, 1995. 2, 3
  7. 7.Thomas Elsken, Jan Hendrik Metzen, and Frank Hutter. Neural architecture search: A survey. The Journal of Machine Learning Research, 20(1):1997–2017, 2019. 4
  8. 8.Yansong Gao, Change Xu, Derui Wang, Shiping Chen, Damith C Ranasinghe, and Surya Nepal. Strip: A defence against trojan attacks on deep neural networks. In Proceedings of the 35th Annual Computer Security Applications Conference, pages 113–125, 2019. 2, 3, 7
  9. 9.Tianyu Gu, Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg. Badnets: Evaluating backdooring attacks on deep neural networks. IEEE Access, 7:47230–47244, 2019. 1, 2, 6
  10. 10.Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. Deep residual learning for image recognition. In Proceedings of CVPR, pages 770–778, 2016. 1
  11. 11.Geoffrey Hinton, Oriol Vinyals, Jeff Dean, et al. Distilling the knowledge in a neural network. arXiv preprint arXiv:1503.02531, 2(7), 2015. 3
  12. 12.Hossein Hosseini and Radha Poovendran. Semantic adversarial examples. In Proceedings of CVPR Workshops, June 2018. 2, 4
  13. 13.Wenbo Jiang, Hongwei Li, Sen Liu, Xizhao Luo, and Rongxing Lu. Poisoning and evasion attacks against deep learning algorithms in autonomous vehicles. IEEE transactions on vehicular technology, 69(4):4439–4449, 2020. 1
  14. 14.Wenbo Jiang, Tianwei Zhang, Han Qiu, Hongwei Li, and Guowen Xu. Incremental learning, incremental backdoor threats. IEEE Transactions on Dependable and Secure Computing, pages 1–11, 2022. 1
  15. 15.Cassidy Laidlaw and Soheil Feizi. Functional adversarial attacks. In Proceedings of NIPS, volume 32, 2019. 4
  16. 16.Yichong Leng, Xu Tan, Linchen Zhu, Jin Xu, Renqian Luo, Linquan Liu, Tao Qin, Xiangyang Li, Edward Lin, and Tie-Yan Liu. Fastcorrect: Fast error correction with edit alignment for automatic speech recognition. In Proceedings of NIPS, volume 34, 2021. 1
  17. 17.Shaofeng Li, Minhui Xue, Benjamin Zi Hao Zhao, Haojin Zhu, and Xinpeng Zhang. Invisible backdoor attacks on deep neural networks via steganography and regularization. IEEE Transactions on Dependable and Secure Computing, 18(5):2088–2105, 2020. 1, 2, 6
  18. 18.Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li, and Xingjun Ma. Neural attention distillation: Erasing backdoor triggers from deep neural networks. arXiv preprint arXiv:2101.05930, 2021. 3
  19. 19.Yiming Li, Tongqing Zhai, Baoyuan Wu, Yong Jiang, Zhifeng Li, and Shutao Xia. Rethinking the trigger of backdoor attack. arXiv preprint arXiv:2004.04692, 2020. 1, 2, 3, 6
  20. 20.Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg. Fine-pruning: Defending against backdooring attacks on deep neural networks. In International Symposium on Research in Attacks, Intrusions, and Defenses, pages 273–294. Springer, 2018. 2, 3, 7
  21. 21.Yingqi Liu, Wen-Chuan Lee, Guanhong Tao, Shiqing Ma, Yousra Aafer, and Xiangyu Zhang. Abs: Scanning neural networks for back-doors by artificial brain stimulation. In Proceedings of CCS, pages 1265–1282, 2019. 1, 2, 6
  22. 22.Yunfei Liu, Xingjun Ma, James Bailey, and Feng Lu. Reflection backdoor: A natural backdoor attack on deep neural networks. In Proceedings of ECCV, pages 182–199, 2020. 1, 2, 6
  23. 23.Tuan Anh Nguyen and Anh Tran. Input-aware dynamic backdoor attack. In Proceedings of NIPS, volume 33, pages 3454–3464, 2020. 6, 7
  24. 24.Tuan Anh Nguyen and Anh Tuan Tran. Wanet-imperceptible warping-based backdoor attack. In Proceedings of ICLR, 2020. 2, 6, 7, 8
  25. 25.Han Qiu, Yi Zeng, Shangwei Guo, Tianwei Zhang, Meikang Qiu, and Bhavani Thuraisingham. Deepsweep: An evaluation framework for mitigating dnn backdoor attacks using data augmentation. In Proceedings of Asia CCS, pages 363–377, 2021. 1, 3, 6
  26. 26.Esteban Real, Alok Aggarwal, Yanping Huang, and Quoc V Le. Regularized evolution for image classifier architecture search. In Proceedings of AAAI, volume 33, pages 4780–4789, 2019. 4
  27. 27.Yankun Ren, Longfei Li, and Jun Zhou. Simtrojan: Stealthy backdoor attack. In 2021 IEEE International Conference on Image Processing (ICIP), pages 819–823. IEEE, 2021. 1, 2, 3, 6
  28. 28.Marco Tulio Ribeiro, Sameer Singh, and Carlos Guestrin. " why should i trust you?" explaining the predictions of any classifier. In Proceedings of the 22nd ACM SIGKDD international conference on knowledge discovery and data mining, pages 1135–1144, 2016. 2
  29. 29.Ramprasaath R Selvaraju, Michael Cogswell, Abhishek Das, Ramakrishna Vedantam, Devi Parikh, and Dhruv Batra. Grad-cam: Visual explanations from deep networks via gradient-based localization. In Proceedings of ICCV, pages 618–626, 2017. 2, 3, 7
  30. 30.Giorgio Severi, Jim Meyer, Scott Coull, and Alina Oprea. {Explanation-Guided} backdoor poisoning attacks against malware classifiers. In Proceedings of USENIX Security Symposium, pages 1487–1504, 2021. 1
  31. 31.Brandon Tran, Jerry Li, and Aleksander Madry. Spectral signatures in backdoor attacks. In Proceedings of NIPS, volume 31, 2018. 2, 8
  32. 32.Gregory K Wallace. The jpeg still picture compression standard. IEEE transactions on consumer electronics, 38(1):1–17, 1992. 6
  33. 33.Sheng Wan, Tung-Yu Wu, Heng-Wei Hsu, Wing Hung Wong, and Chen-Yi Lee. Feature consistency training with jpeg compressed images. IEEE Transactions on Circuits and Systems for Video Technology, 30(12):4769–4780, 2019. 2
  34. 34.Bolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li, Bimal Viswanath, Haitao Zheng, and Ben Y Zhao. Neural cleanse: Identifying and mitigating backdoor attacks in neural networks. In Proceedings of S&P, pages 707–723, 2019. 2, 3, 7
  35. 35.Zhou Wang, Alan C Bovik, Hamid R Sheikh, and Eero P Simoncelli. Image quality assessment: from error visibility to structural similarity. IEEE transactions on image processing, 13(4):600–612, 2004. 2, 3, 4
  36. 36.Emily Wenger, Josephine Passananti, Arjun Nitin Bhagoji, Yuanshun Yao, Haitao Zheng, and Ben Y Zhao. Backdoor attacks against deep learning systems in the physical world. In Proceedings of CVPR, pages 6206–6215, 2021. 1
  37. 37.Mingfu Xue, Xin Wang, Shichang Sun, Yushu Zhang, Jian Wang, and Weiqiang Liu. Compression-resistant backdoor attack against deep neural networks. arXiv preprint arXiv:2201.00672, 2022. 1, 2, 3, 6
  38. 38.Kota Yoshida and Takeshi Fujino. Disabling backdoor and identifying poison data by using knowledge distillation in backdoor attacks on deep neural networks. In Proceedings of the 13th ACM Workshop on Artificial Intelligence and Security, pages 117–127, 2020. 3
  39. 39.Tongqing Zhai, Yiming Li, Ziqi Zhang, Baoyuan Wu, Yong Jiang, and Shu-Tao Xia. Backdoor attack against speaker verification. In Proceedings of ICASSP, pages 2560–2564. IEEE, 2021. 1
  40. 40.Jie Zhang, Dongdong Chen, Jing Liao, Qidong Huang, Gang Hua, Weiming Zhang, and Nenghai Yu. Poison ink: Robust and invisible backdoor attack. arXiv preprint arXiv:2108.02488, 2021. 2
  41. 41.Michael Zhang, James Lucas, Jimmy Ba, and Geoffrey E Hinton. Lookahead optimizer: k steps forward, 1 step back. Proceedings of NIPS, 32, 2019. 3
  42. 42.Richard Zhang, Phillip Isola, Alexei A Efros, Eli Shechtman, and Oliver Wang. The unreasonable effectiveness of deep features as a perceptual metric. In Proceedings of CVPR, pages 586–595, 2018. 2, 3, 4
  43. 43.Pu Zhao, Pin-Yu Chen, Payel Das, Karthikeyan Natesan Ramamurthy, and Xue Lin. Bridging mode connectivity in loss landscapes and adversarial robustness. In Proceedings of ICLR, 2020. 3
  44. 44.Zhendong Zhao, Xiaojun Chen, Yuexin Xuan, Ye Dong, Dakui Wang, and Kaitai Liang. Defeat: Deep hidden feature backdoor attacks by imperceptible perturbation and latent representation constraints. In Proceedings of CVPR, pages 15213–15222, 2022. 1, 2, 3, 6
  45. 45.Zhengyu Zhao, Zhuoran Liu, and Martha Larson. Towards large yet imperceptible adversarial image perturbations with perceptual color distance. In Proceedings of CVPR, June 2020. 4
  46. 46.Haoti Zhong, Cong Liao, Anna Cinzia Squicciarini, Sencun Zhu, and David Miller. Backdoor embedding in convolutional neural network models via invisible perturbation. In Proceedings of the Tenth ACM Conference on Data and Application Security and Privacy, pages 97–108, 2020. 1, 2
  47. 47.Barret Zoph, Vijay Vasudevan, Jonathon Shlens, and Quoc V Le. Learning transferable architectures for scalable image recognition. In Proceedings of CVPR, pages 8697–8710, 2018. 4

Citation

MLA
Jiang, W., et al. “Color Backdoor: A Robust Poisoning Attack in Color Space”. 2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 2023, pp. 8133–42, https://doi.org/10.1109/CVPR52729.2023.00786.
APA
Jiang, W., Li, H., Xu, G., & Zhang, T. (2023). Color Backdoor: A Robust Poisoning Attack in Color Space. 2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 8133–8142. https://doi.org/10.1109/CVPR52729.2023.00786
Chicago
Jiang, W., H. Li, G. Xu, and T. Zhang. 2023. “Color Backdoor: A Robust Poisoning Attack in Color Space”. 2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 8133–42. https://doi.org/10.1109/CVPR52729.2023.00786.
Harvard
Jiang, W. et al. (2023) “Color Backdoor: A Robust Poisoning Attack in Color Space”, 2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). IEEE, pp. 8133–8142. Available at: https://doi.org/10.1109/CVPR52729.2023.00786.
Vancouver
1. Jiang W, Li H, Xu G, Zhang T (2023) Color Backdoor: A Robust Poisoning Attack in Color Space. In: 2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). IEEE, pp 8133–8142

BibTeX

@inproceedings{Jiang_2023, title={Color Backdoor: A Robust Poisoning Attack in Color Space}, url={http://dx.doi.org/10.1109/CVPR52729.2023.00786}, DOI={10.1109/cvpr52729.2023.00786}, booktitle={2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)}, publisher={IEEE}, author={Jiang, Wenbo and Li, Hongwei and Xu, Guowen and Zhang, Tianwei}, year={2023}, month=June, pages={8133–8142} }
Metadata:Crossref

Access the Paper

This paper is available from its original source. Click below to access the PDF.

Open PDF
License: IEEE