Abstract
Face recognition is often used for biometric validation, which has become a significant technique in our society. Due to its sensitive applications, security vulnerabilities posed by backdoor attacks have attracted considerable focus. Current backdoor attack methods use digital perturbations or physical objects as triggers, while these additional requirements make existing backdoor attacks less viable in real-world applications. To address this issue, we propose a novel backdoor attack method named Scene Backdoor (Scenedoor), which injects a 3D scene as the trigger that effectively simplifies the backdoor activation. Any person who appears in this scene will be attacked as the attacker-desired identity. Specifically, we reconstruct a 3D scene from several 2D images and then blend the facial part extracted from the input sample with the reconstructed scene to generate the poisoned image. Extensive experiments are conducted on CelenDF (v2), CelebA-HQ, and PinsFace datasets, demonstrating that Scenedoor overtakes five state-of-the-art methods in terms of effectiveness, stealthiness, and robustness.
Original language | English |
---|---|
Title of host publication | 2024 IEEE International Conference on Visual Communications and Image Processing (VCIP) |
Publisher | IEEE |
Number of pages | 5 |
ISBN (Electronic) | 9798331529543 |
ISBN (Print) | 9798331529550 |
DOIs | |
Publication status | Published - 8 Dec 2024 |
Event | 2024 IEEE International Conference on Visual Communications and Image Processing, VCIP 2024 - Tokyo, Japan Duration: 8 Dec 2024 → 11 Dec 2024 https://ieeexplore.ieee.org/xpl/conhome/10849624/proceeding |
Publication series
Name | IEEE International Conference on Visual Communications and Image Processing |
---|---|
Publisher | IEEE |
ISSN (Print) | 2642-9357 |
ISSN (Electronic) | 1018-8770 |
Conference
Conference | 2024 IEEE International Conference on Visual Communications and Image Processing, VCIP 2024 |
---|---|
Country/Territory | Japan |
City | Tokyo |
Period | 8/12/24 → 11/12/24 |
Internet address |
User-Defined Keywords
- Backdoor attack
- scene backdoor
- face recognition
- Neural Radiance Fields