Backdoor Attacks on Deep Learning Face Detection

📅 2025-08-01
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses backdoor attacks against deep learning-based face detectors in unconstrained scenarios. We propose two novel attack paradigms specifically targeting coordinate regression tasks: Face Generation Attack and Landmark Shift Attack—the latter being the first backdoor framework designed exclusively for facial landmark regression. By embedding stealthy triggers into both bounding-box localization and landmark coordinate prediction modules, the attacks significantly degrade detection accuracy on poisoned inputs while preserving clean-input performance. Extensive experiments on mainstream models—including RetinaFace and MTCNN—demonstrate high attack stealthiness and effectiveness. Furthermore, we design a targeted defense mechanism that substantially improves model robustness against such coordinate-regression backdoors without compromising generalization. Our study exposes critical security vulnerabilities in coordinate-regression visual models and provides new insights for backdoor defense in detection-oriented architectures.

Technology Category

Application Category

📝 Abstract
Face Recognition Systems that operate in unconstrained environments capture images under varying conditions,such as inconsistent lighting, or diverse face poses. These challenges require including a Face Detection module that regresses bounding boxes and landmark coordinates for proper Face Alignment. This paper shows the effectiveness of Object Generation Attacks on Face Detection, dubbed Face Generation Attacks, and demonstrates for the first time a Landmark Shift Attack that backdoors the coordinate regression task performed by face detectors. We then offer mitigations against these vulnerabilities.
Problem

Research questions and friction points this paper is trying to address.

Backdoor attacks on face detection systems
Landmark shift attacks affecting coordinate regression
Mitigating vulnerabilities in unconstrained environments
Innovation

Methods, ideas, or system contributions that make the work stand out.

Object Generation Attacks on Face Detection
Landmark Shift Attack on coordinate regression
Mitigations against Face Generation Attacks
🔎 Similar Papers
No similar papers found.
Q
Quentin Le Roux
Thales Cyber & Digital, Inria/Univ. de Rennes
Yannick Teglia
Yannick Teglia
Cybersecurity Principal Engineer - Thales DIS
CybersecurityArtificial IntelligenceCryptography
Teddy Furon
Teddy Furon
INRIA Rennes - IRISA
multimedia security
P
Philippe Loubet Moundi
Thales Cyber & Digital