Supplementary Materials A Extended Related Work (2)

Neural Information Processing Systems 

We first discuss attacks that use physical objects as triggers, then discuss a few related works which use light as a trigger. We conclude by discussing the single proposed defense against physical backdoor attacks. As mentioned briefly in 2, [ 10 ] designs a backdoor attack against lane detection systems for autonomous vehicles. This attack expands the scope of physical backdoor attacks by attacking detection rather than classification models. Furthermore, it confirms the result from [ 43 ] that even when digitally altered images are used to poison a dataset, the triggers can be activated using physical objects (traffic cones in this setting) in real world scenarios. A second work [ 31 ] evaluates the effectiveness of using facial characteristics as backdoor triggers.

Similar Docs  Excel Report  more

TitleSimilaritySource
None found