Stealthy Backdoor Attack against Video Recognition Models
Jiale Yan, Bo Zhao, Chunyu Yang
Abstract
Deep neural networks have achieved great success in various domains, however, it is fragile against backdoor attacks. Currently, the backdoor attack method in video recognition mainly comes from the expansion of the field of image classification, it faces the challenge that the trigger can be perceived by human eyes and easily captured by the defense methods in the existing image field. To solve the above challenges, in this paper, we propose a Stealthy Backdoor Attack method against Video Action Recognition model (SBAVAR), which improves the imperceptibility and effectiveness of backdoor triggers, enhancing their threat. Specifically, we formalize backdoor trigger generation as an optimization problem and utilize a feasible optimization scheme that integrates sparse spatial transformation perturbation and additive perturbation to generate a trigger, ensuring the imperceptibility and effectiveness of backdoor attacks. Our intensive experiments show that SBAVAR can achieve superior imperceptibility and effectiveness compared with baseline method. Additionally, SBAVAR can circumvent the existing backdoor defense methods.
BibTeX
@inproceedings{icassp2025_stealthybackdoor,
title = {Stealthy Backdoor Attack against Video Recognition Models},
author = {Jiale Yan and Bo Zhao and Chunyu Yang},
booktitle = {ICASSP 2025},
year = {2025}
}