1 of 1

Moiré Backdoor Attack (MBA):

A Novel Trigger for Pedestrian Detectors in the Physical World

Hui Wei1, Hanxun Yu1, Kewei Zhang1, Zhixiang Wang2, Jianke Zhu3, Zheng Wang1

1Wuhan University, 2The University of Tokyo, 3Zhejiang University

Proposed Method

Experiment Results and Visualization

Motivation

Contribution

Background

  • Backdoor Attack:

Manipulate the DNNs-based model by injecting

a backdoor.

  • Topic:

Physical Backdoor Attack, Pedestrian Detectors.

  • Challenge:

Stealthy and effective trigger:

  • Moiré patterns:

are a common interference in digital images

that typically go unnoticed.

  • Stealthiness:

Moiré patterns are imperceptible to the human

eye and only occur when imaged by sensors.

  • Pattern features:

These patterns exhibit irregularity.

  • We are the first to use Moiré patterns as triggers for physical backdoor attacks, enabling individuals wearing clothes with Moiré patterns to evade detection in the real world.

  • Our method integrates a physical simulation of Moiré patterns on clothes. It gives attackers freedom and flexibility to manipulate DNNs using any clothing with Moiré patterns.

  • Experimental results indicate the effectiveness of the proposed method.
  • Generate Moiré patterns

Moiré patterns = Texture of

the clothing + Camera

Sensor CCD pixel grid.

  • Synthetic Moiré patterns
  • Attack effectiveness in the digital world
  • Attack effectiveness in the physical world
  • Attack stealthiness comparison

clothing1

clothing2

  • Effect of proportion coefficient
  • Effect of training epoch
  • Defense discussion