Position-Independent and Stealthy Backdoor Attack of IMU Systems

Zhiwei Chen, Qun Niu · 2024

Deep neural networks are widely employed in various inertial measurement units (IMUs) based motion analysis systems, including activity recognition, user authentication, and healthcare. However, the security risks of current IMU systems have not been thoroughly studied. In this paper, we present a backdoor attack for IMU sequences. We first introduce methods for generating poisoned samples using patching and fusion procedures for IMUs. Despite the effectiveness, patching and fusion requires pre-determined starting position in IMU sequences and is distinguishing from the rest. To address these limitations, we further propose a novel joint optimization scheme for generating position-independent IMU patterns that can attack at arbitrary positions in the IMU sequence. Furthermore, we incorporate the penalty of geometrical consistency into the optimization and encourage stealthy perturbations as IMU patterns. We validate our proposed backdoor attack in two dominant tasks of IMU-based motion analysis systems: human activity recognition (HAR) and user authentication (UA). Experimental results demonstrate that IMU systems are prone to be attacked by optimized IMU patterns (attack success rate up to 90% at extremely low positioning rate 2%) across different deep neural network architectures and two datasets on both tasks, highlighting the security risks inherent in current IMU systems.

Read the paper · More papers on PaperTik