A novel backdoor attack method that utilizes visible, semantic, sample-specific, and compatible triggers to achieve effective, stealthy, and robust backdoor attacks in both digital and physical scenarios.
SATBA proposes an imperceptible backdoor attack using spatial attention, overcoming limitations of existing methods and ensuring high attack success rate.
The author proposes SATBA, an invisible backdoor attack using spatial attention and U-net to overcome limitations of existing methods, achieving high attack success rates while maintaining robustness against defenses.