BadSTR: Backdoor Attack on Scene Text Recognition in IoT

Qiuhua Wang, Yifan Hu, Xiyuan Jia, Guohua Wu, Yizhi Ren, Gaoning Pan, Yanyu Cheng · IEEE Internet of Things Journal · 2025

Recent researches have shown that non-sequential tasks based on deep neural networks (DNN), such as image classification and object detection, are vulnerable to backdoor attacks, leading to incorrect model predictions. As a crucial task in computer vision, Scene Text Recognition (STR) is widely used in IoT fields such as intelligent transportation systems and intelligent surveillance. Given its importance, ensuring the security and accuracy of STR models is critical. However, there are currently no studies on STR backdoor attacks. In this paper, we make the first attempt to validate backdoor threats on STR models by using a Patch-Based Attack method. Our experimental results confirm that STR models can be successfully compromised with attack success rate (ASR) of over 80% on most datasets. However, we also reveal a critical flaw: the Patch-Based attack lacks robustness due to the specific preprocessing in STR models (such as resizing and TPS rectification), which distort or eliminate the backdoor triggers. To address this, we further propose BadSTR, a novel backdoor attack method that uses semantic text sequences as triggers. Extensive experiments on eight benchmark datasets show that our proposed BadSTR achieves ASR of over 90% for most model-dataset combinations with significantly improved robustness.

Read the paper · More papers on PaperTik