Search papers, labs, and topics across Lattice.
This paper introduces FIDA, a novel backdoor attack framework targeting self-supervised facial representation models, which are often overlooked in discussions of SSL vulnerabilities. By employing subtle semantic triggers and a unique Feature Instability Loss objective, FIDA increases the sensitivity of triggered features, allowing the attack to evade conventional defenses. Experimental results demonstrate that FIDA not only achieves a high attack success rate but also maintains benign utility, highlighting its potential threat to real-world applications in facial analysis.
FIDA's innovative approach allows backdoor attacks to evade traditional defenses while preserving the functionality of facial recognition systems.
Self-supervised learning (SSL) models are vulnerable to backdoor attacks. However, the systemic risks they pose in face representation have received little attention. The entanglement of identity features in self-supervised face learning presents unique challenges for attack stealthiness. To address this gap, we propose FIDA (Feature Instability-Driven Attack), a novel backdoor attack framework. FIDA uses subtle semantic triggers for injection, but its key innovation is a novel objective called Feature Instability Loss. It trains the encoder to increase the sensitivity of triggered features along perturbation directions sampled during attack optimization . By preventing the backdoor from exhibiting the rigid feature patterns typical of previous attacks, FIDA effectively evades the evaluated perturbation-based defenses. Experiments show that FIDA achieves a high attack success rate and generally preserves benign utility across the evaluated settings , posing a significant threat to real-world multimedia applications relying on facial analysis.