TrojanNet Attack on Human Pose Estimation Networks

Qianxi Qiu, Fuchang Liu · 2024

Human pose estimation has achieved significant progress in recent years. However, recent research exploits advanced network structures to improve performance on benchmark datasets, ignoring the vulnerability to adversarial attack. In this paper, we propose a backdoor attack method via injecting a Trojan network into victim human pose estimation networks, without retraining networks and easily to be deployed by the user. Additionally, we design an imperceptible trigger pattern for Trojan attack with semantic perturbation meaning. Experiments on the MS COCO dataset demonstrate our method achieves at least 0.2 AP score drop and maintains the performance on clean inputs against state-of-the art human pose estimation networks. Experiments have proved that the backdoor attack method for human pose estimation network is effective and harmful.

Read the paper · More papers on PaperTik