Pith. sign in

REVIEW 2 cited by

Backdoor Attack in the Physical World

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2104.02361 v2 pith:QR2H4IJO submitted 2021-04-06 cs.CR cs.AIcs.CV

classification cs.CRcs.AIcs.CV
keywords backdoorattacktriggertrainingappearanceattackshiddenimages
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

Backdoor attack intends to inject hidden backdoor into the deep neural networks (DNNs), such that the prediction of infected models will be maliciously changed if the hidden backdoor is activated by the attacker-defined trigger. Currently, most existing backdoor attacks adopted the setting of static trigger, $i.e.,$ triggers across the training and testing images follow the same appearance and are located in the same area. In this paper, we revisit this attack paradigm by analyzing trigger characteristics. We demonstrate that this attack paradigm is vulnerable when the trigger in testing images is not consistent with the one used for training. As such, those attacks are far less effective in the physical world, where the location and appearance of the trigger in the digitized image may be different from that of the one used for training. Moreover, we also discuss how to alleviate such vulnerability. We hope that this work could inspire more explorations on backdoor properties, to help the design of more advanced backdoor attack and defense methods.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Lilith: Backdoor Generalization under Training-Inference Trigger Shift

    cs.CR 2026-07 conditional novelty 7.0 of 10

    A single poisoned training trigger can create a backdoor that fires for a whole family of unseen inference-time triggers, provided the variants preserve the anchor's representation geometry.

  2. BadDepth: Backdoor Attacks Against Monocular Depth Estimation in the Physical World

    cs.CV 2025-05 conditional novelty 6.0 of 10

    BadDepth uses poisoned depth labels and physical-world image augmentation to make a triggered object vanish from monocular depth predictions.

Pith tools