Covert backdoor attack framework for UAV object detection
Received date: 2024-12-19
Online published: 2025-03-19
Copyright
With the booming development of low-altitude economy and unmanned aerial vehicle (UAV) technology, the deep learning based object detection model has been widely used in the field of UAVs, however, with potential security threats in practical deployment. Distinguished from the traditional image classification, the object detection model additionally generates and returns a set of labeled bounding boxes on the basis of identifying objects. Utilizing this feature, a covert backdoor attack framework for object detection model was proposed. Different from the traditional backdoor attack methods that only embed specific trigger features in images, the proposed new framework precisely matched the object categories of images with bounding box labels firstly. Then, based on the matching results, the data and labels were selectively poisoned according to the image scaling principle, achieving high stealthiness of backdoor implantation. Finally, the experimental results demonstrated that the proposed backdoor attack method was with high attack success rate on the real datasets.
Key words: UAV; deep learning; object detection model; image-scaling attacks; backdoor attacks
CHEN Tianxin , JIANG Wenbo , WEN Jiayi , MI Jiatong , HUANG Cheng . Covert backdoor attack framework for UAV object detection[J]. Journal of Cybersecurity, 2025 , 3(1) : 19 -29 . DOI: 10.20172/j.issn.2097-3136.250102
表 1 实验环境的配置信息Table 1 Configuration information of the experiment |
| 环境配置 | 具体参数 |
| PyTorch | 2.1.0 |
| Python | 3.8 |
| Cuda | 12.4 |
| CPU | Intel Xeon Gold |
| 系统环境 | Ubuntu20.04 |
| GPU | RTX |
| 显存 | 24 GB |
表 2 不同攻击方式的ASR和mAPTable 2 ASR and mAP of different attack methods |
| 攻击方式 | 具体内容 | ASR | mAP50 |
| 攻击方式一 | 嵌入目标+修改标注 | 87.30% | 93.51% |
| 仅修改标注 | 50.79% | 93.90% | |
| 攻击方式二 | 嵌入图像+修改标注 | 100% | 94.56% |
| 对类别12嵌入目标 | 21.10% | 79.02% |
| 1 |
那振宇, 程留洋, 孙鸿晨, 等. 基于深度学习的无人机检测和识别研究综述[J]. 信号处理, 2024, 40 (4): 609- 624.
NA Z Y, CHENG L Y, SUN H C, et al. A review of research on drone detection and recognition based on deep learning[J]. Journal of Signal Processing, 2024, 40 (4): 609- 624.
|
| 2 |
CARION N,MASSA F,SYNNAEVE G,et al. End-to-end object detection with transformers[C]//European Conference on Computer Vision. Cham:Springer International Publishing,2020:213-229.
|
| 3 |
REDMON J,DIVVALA S,GIRSHICK R,et al. You only look once:Unified,real-time object detection[C]//Proceedings of The IEEE Conference on Computer Vision and Pattern Recognition. IEEE,2016:779-788.
|
| 4 |
NING Z,LI T,WU Y,et al. 6G communication new paradigm:the integration of unmanned aerial vehicles and intelligent reflecting surfaces[J]. IEEE Communications Surveys & Tutorials,2025:1-1.
|
| 5 |
FARAJIJALAL M, ESLAMIAT H, AVINENI V, et al. Safety systems for emergency landing of civilian unmanned aerial vehicles-a comprehensive review[J]. Drones, 2025, 9 (2): 141.
|
| 6 |
ZHU C,FAN X,DENG X,et al. Energy-efficient and privacy-preserving edge intelligence for 6G-empowered intelligent transportation systems[J]. IEEE Network,2025:1-1.
|
| 7 |
ASKARZADEH T, BRIDGELALL R, TOLLIVER D D. Drones for road condition monitoring: Applications and benefits[J]. Journal of Transportation Engineering, Part B: Pavements, 2025, 151 (1): 04024055.
|
| 8 |
CHENG S,SHEN G,TAO G,et al. Odscan:Backdoor scanning for object detection models[C]//2024 IEEE Symposium on Security and Privacy (SP). IEEE,2024:1703-1721.
|
| 9 |
CHAN S H,DONG Y,ZHU J,et al. Baddet:Backdoor attacks on object detection[C]//European Conference on Computer Vision. Cham:Springer Nature Switzerland,2022:396-412.
|
| 10 |
LUO C,LI Y,JIANG Y,et al. Untargeted backdoor attack against object detection[C]//ICASSP 2023-2023 IEEE International Conference on Acoustics,Speech and Signal Processing (ICASSP). IEEE,2023:1-5.
|
| 11 |
GU T, LIU K, DOLAN-GAVITT B, et al. Badnets: Evaluating backdooring attacks on deep neural networks[J]. IEEE Access, 2019, 7, 47230- 47244.
|
| 12 |
CHEN K,LOU X,XU G,et al. Clean-image backdoor:Attacking multi-label models with poisoned labels only[C]//The Eleventh International Conference on Learning Representations. ICLR,2022. https://openreview.net/forum?id=rFQfjDC9Mt.
|
| 13 |
QUIRING E,RIECK K. Backdooring and poisoning neural networks with image-scaling attacks[C]//2020 IEEE Security and Privacy Workshops (SPW). IEEE,2020:41-47.
|
| 14 |
XIAO Q,CHEN Y,SHEN C,et al. Seeing is not believing:Camouflage attacks on image scaling algorithms[C]//28th USENIX Security Symposium (USENIX Security 19). 2019:443-460.
|
| 15 |
DUONG T T N,BUI D N,PHUNG M D. Navigation variable-based multi-objective particle swarm optimization for UAV path planning with kinematic constraints[J]. Neural Computing and Applications,2025:1-15.
|
| 16 |
BOCHKOVSKIY A, WANG C Y, LIAO H Y M. Yolov4: Optimal speed and accuracy of object detection[J]. ArXiv preprint, ArXiv:, 2004, 10934, 2020.
|
| 17 |
JOCHER G,QIU J,CHAURASIA A. Ultralytics YOLO[CP/OL]. https://github.com/ultralytics/ultralytics.
|
| 18 |
HUANG S, PAPERNOT N, GOODFELLOW I, et al. Adversarial attacks on neural network policies[J]. ArXiv preprint, ArXiv:, 1702, 02284, 2017.
|
| 19 |
JIN K, ZHANG T, SHEN C, et al. Can we mitigate backdoor attack using adversarial detection methods?[J]. IEEE Transactions on Dependable and Secure Computing, 2022, 20 (4): 2867- 2881.
|
| 20 |
GOODFELLOW I, POUGET-ABADIE J, MIRZA M, et al. Generative adversarial networks[J]. Communications of the ACM, 2020, 63 (11): 139- 144.
|
| 21 |
GARG S,KUMAR A,GOEL V,et al. Can adversarial weight perturbations inject neural backdoors[C]//Proceedings of the 29th ACM International Conference on Information & Knowledge Management. 2020:2029-2032.
|
| 22 |
CHAKRABORTY A, ALAM M, DEY V, et al. A survey on adversarial attacks and defences[J]. CAAI Transactions on Intelligence Technology, 2021, 6 (1): 25- 45.
|
| 23 |
LI J, CHEN H, SUN P, et al. Call white black: Enhanced image-scaling attack in industrial artificial intelligence systems[J]. IEEE Transactions on Industrial Informatics, 2024, 20 (4): 6222- 6233.
|
| 24 |
QUIRING E,MÜLLER A,RIECK K. On the detection of image-scaling attacks in machine learning[C]//Proceedings of the 39th Annual Computer Security Applications Conference. 2023:506-520. https://dl.acm.org/doi/10.1145/3627106.3627134.
|
| 25 |
CARLINI N, TERZIS A. Poisoning and backdooring contrastive learning[J]. ArXiv preprint, ArXiv:, 2106, 09667, 2021.
|
| 26 |
LI Y, JIANG Y, LI Z, et al. Backdoor learning: A survey[J]. IEEE Transactions on Neural Networks and Learning Systems, 2022, 35 (1): 5- 22.
|
| 27 |
LI Y,LI Y,WU B,et al. Invisible backdoor attack with sample-specific triggers[C]//Proceedings of the IEEE/CVF International Conference on Ccomputer Vision. IEEE,2021:16463-16472.
|
| 28 |
HUANG H,MU J,GONG N Z,et al. Data poisoning attacks to deep learning based recommender systems[C]//Network and Distributed Systems Security Symposium. 2021.
|
| 29 |
DOAN K, LAO Y, LI P. Backdoor attack with imperceptible input and latent modification[J]. Advances in Neural Information Processing Systems, 2021, 34, 18944- 18957.
|
| 30 |
TRAN B, LI J, MADRY A. Spectral signatures in backdoor attacks[J]. Advances in Neural Information Processing systems, 2018, 31, 8011- 8021.
|
| 31 |
Traffic signs detection[EB/OL]. https://www.kaggle.com/datasets/pkdarabi/cardetection.
|
/
| 〈 |
|
〉 |