PUBA: A Physical Undirected Backdoor Attack in Vision-based UAV Detection and Tracking Systems

Haoyu Jiang, Nan Li, Ping Yi · 2024

As artificial intelligence advances, deep learning and machine vision technologies have been widely applied in unmanned aerial vehicle (UAV) platforms for tasks such as target tracking and visual avoidance. The reliability of drones equipped with AI models is critically dependent on the security of these models. The training of AI models often requires substantial computational resources and typically relies on third-party platforms for computational power, datasets, and pre-trained models. This reliance creates opportunities for AI backdoor attacks, posing security risks to AI-powered drones. This paper introduces a novel undirected physical backdoor attack method, PUBA, that utilizes target disappearance and false target generation to poison labels. By integrating data poisoning techniques, PUBA implements backdoor attacks in physical space, collects datasets in the real world, trains backdoor models, and evaluates the effectiveness, stealth, and robustness of PUBA in both simulated systems and real drones. This study disrupts the normal execution of target recognition and tracking tasks on drones by poisoning data and implanting backdoors in target recognition models used by UAVs, exposing potential security vulnerabilities in the domain of drone target tracking.

Read the paper · More papers on PaperTik