Effectiveness Analysis of Straight-Line Backdoor Attacks on the Deep Learning Model
Downloads
Deep learning models, particularly Convolutional Neural Networks (CNNs), are increasingly deployed in safety-critical applications yet remain vulnerable to backdoor attacks. Existing research implicitly assumes that effective backdoor triggers must be complex or imperceptible, overlooking the inherent sensitivity of CNNs to simple low-level visual features. This study investigates the effectiveness of a straight-line trigger a 2-pixel-wide horizontal line at 48% image height with normalized intensity of 0.55 in executing backdoor attacks against a ResNet-34 model trained on the GTSRB traffic sign dataset. Following a data poisoning threat model with an all-to-one attack strategy, experiments are conducted at poison rates of 1%, 3%, and 5%. Results demonstrate that the proposed trigger achieves Attack Success Rates (ASR) of up to 100.00% at the highest evaluated poison rate, with ASR values of 93.82%, 99.77%, and 100.00% at poison rates of 1%, 3%, and 5%, respectively, while maintaining Clean Accuracy (CA) within 1.46 percentage points of the clean baseline (97.75%), with the lowest CA recorded at 96.29% under the 5% poison rate condition. Training dynamics analysis reveals pronounced shortcut learning behavior, with the trigger–target association forming rapidly within the early training epochs and converging well ahead of semantic classification features, prior to the full convergence of clean accuracy. Feature map progression and t-SNE visualizations confirm that triggered inputs are completely remapped to the target class cluster at the representational level, while clean inputs retain their original class-discriminative structure. These findings challenge the prevailing assumption that effective backdoor attacks require sophisticated trigger designs, and highlight the critical security implications of CNN inductive bias toward simple spatial patterns. The simplicity and low cost of the proposed attack underscore the urgent need for backdoor defense mechanisms capable of detecting minimal, low-frequency triggers.
Bai, Y., Xing, G., Wu, H., Rao, Z., Ma, C., Wang, S., Liu, X., Zhou, Y., Tang, J., Huang, K., & Kang, J. (2025). Backdoor Attack and Defense on Deep Learning: A Survey. IEEE Transactions on Computational Social Systems, 12(1), 404–434.
https://doi.org/10.1109/TCSS.2024.3482723
Barni, M., Kallas, K., & Tondi, B. (2019). A New Backdoor Attack in CNNS by Training Set Corruption Without Label Poisoning. Proceedings - International Conference on Image Processing, ICIP, 2019-Septe, 101–105.
https://doi.org/10.1109/ICIP.2019.8802997
Chai, J., Zeng, H., Li, A., & Ngai, E. W. T. (2021). Deep learning in computer vision: A critical review of emerging techniques and application scenarios. Machine Learning with Applications, 6, 100134. https://doi.org/10.24433/CO.0411648.v1
Chan, S. H., Dong, Y., Zhu, J., Zhang, X., & Zhou, J. (2023). BadDet: Backdoor Attacks on Object Detection. Lecture Notes in Computer Science, 13801 LNCS, 396–412. https://doi.org/10.1007/978-3-031-25056-9_26
Chen, X., Liu, C., Li, B., Lu, K., & Song, D. (2017). Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning.
http://arxiv.org/abs/1712.05526
Geirhos, R., Michaelis, C., Zemel, R., Brendel, W., Bethge, M., & Wichmann, F. A. (2020). Shortcut Learning in Deep Neural Networks. Nature Machine Intelligence, 2(11), 665–673.
https://doi.org/10.1038/s42256-020-00257-z
Goldblum, M., Tsipras, D., Xie, C., Chen, X., Schwarzschild, A., Song, D., Madry, A., Li, B., & Goldstein, T. (2023). Dataset Security for Machine Learning: Data Poisoning, Backdoor Attacks, and Defenses. IEEE Transactions on Pattern Analysis and Machine Intelligence, 45(2), 1563–1580.
https://doi.org/10.1109/TPAMI.2022.3162397
Gu, T., Dolan-Gavitt, B., & Garg, S. (2017). BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain.
http://arxiv.org/abs/1708.06733
He, K., Zhang, X., Ren, S., & Sun, J. (2016). Deep residual learning for image recognition. Proceedings of the IEEE Computer Society Conference on Computer Vision and Pattern Recognition, 2016-Decem, 770–778.
https://doi.org/10.1109/CVPR.2016.90
Li, Y., Jiang, Y., Li, Z., & Xia, S. T. (2024). Backdoor Learning: A Survey. IEEE Transactions on Neural Networks and Learning Systems, 35(1),
–22. https://doi.org/10.1109/TNNLS.2022.3182979
Li, Y., Li, Y., Wu, B., Li, L., He, R., & Lyu, S. (2021). Invisible Backdoor Attack with Sample-Specific Triggers. Proceedings of the IEEE International Conference on Computer Vision, 16443–16452. https://doi.org/10.1109/ICCV48922.2021.01615
Li, Y., Zhang, S., Wang, W., & Song, H. (2023). Backdoor Attacks to Deep Learning Models and Countermeasures: A Survey. IEEE Open Journal of the Computer Society, 4, 134–146.
https://doi.org/10.1109/OJCS.2023.3267221
Liu, Y., Ma, X., Bailey, J., & Lu, F. (2020). Reflection Backdoor: A Natural Backdoor Attack on Deep Neural Networks. Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 12355 LNCS, 182–199.
https://doi.org/10.1007/978-3-030-58607-2_11
Mengara, O., Avila, A., & Falk, T. H. (2024). Backdoor Attacks to Deep Neural Networks: A Survey of the Literature, Challenges, and Future Research Directions. IEEE Access, 12, 29004–
https://doi.org/10.1109/ACCESS.2024.3355816
Taye, M. M. (2023). Theoretical Understanding of Convolutional Neural Network: Concepts, Architectures, Applications, Future Directions. Computation, 11(3).
https://doi.org/10.3390/computation11030052
Turner, A., Tsipras, D., & Madry, A. (2019). Label-Consistent Backdoor Attacks. 1–24.
http://arxiv.org/abs/1912.02771
Wang, Y., Zhao, M., Li, S., Yuan, X., & Ni, W. (2022). Dispersed Pixel Perturbation-Based Imperceptible Backdoor Trigger for Image Classifier Models. IEEE Transactions on Information Forensics and Security, 17, 3091–3106. https://doi.org/10.1109/TIFS.2022.3202687
Zhao, P., Zhu, W., Jiao, P., Gao, D., & Wu, O. (2025). Data Poisoning in Deep Learning: A Survey. 1–20. http://arxiv.org/abs/2503.22759
