BadAction:通过动作引导触发器对交互式视频生成进行后门攻击
BadAction: Backdoor Attacks on Interactive Video Generation via Action-Guided Triggers
查看机构详情
- University of Chinese Academy of Sciences(中国科学院大学)
机构由 AI 辅助整理,请以论文原文为准。
浏览论文内容
中文总结 AI 辅助
本文首次系统研究交互式视频生成模型的后门攻击,提出BadAction方法,通过动作引导触发器植入恶意行为,使模型在触发时生成冻结帧,平均攻击成功率高达91.0%,并成功绕过现有防御。
中文摘要 AI 辅助
交互式视频生成(IVG)模型在根据用户定义的动作生成可控视觉内容方面取得了显著进展,但其安全漏洞在很大程度上仍未得到探索。在本文中,我们首次对针对IVG模型交互性的后门攻击进行了系统性研究。基于这一攻击面,我们提出了BadAction,它利用动作引导的触发器来实现攻击。具体来说,BadAction将预定义的运动模式植入后门样本的动作序列中,并将其与一个静态目标视频相关联。一旦被触发,被植入后门的模型会生成冻结的未来帧,不再响应用户后续的动作,同时在对良性动作序列时保持正常行为。此外,我们还探索了一种更隐蔽的攻击,其中多模态触发器联合污染动作、文本和图像输入。实验表明,BadAction在仅使用动作触发器时平均攻击成功率达到91.0%,在使用多模态触发器时达到80.4%。此外,广泛的防御评估表明,BadAction成功绕过了现有的后门检测方法,揭示了交互式视频生成流程中一个关键的安全漏洞。项目页面:此https URL。
英文摘要
Interactive video generation (IVG) models have achieved remarkable progress in producing controllable visual content guided by user-defined actions, yet their security vulnerabilities remain largely unexplored. In this paper, we present the first systematic study of backdoor attacks against the interactivity of IVG models. Based on this attack surface, we propose BadAction, which leverages action-guided triggers to achieve the attack. Specifically, BadAction implants predefined motion patterns into the action sequences of backdoor samples and associates them with a static target video. Once triggered, the backdoored model generates frozen future frames that no longer respond to subsequent user actions, while preserving normal behavior on benign action sequences. In addition, we explore a stealthier attack in which multimodal triggers jointly poison action, text, and image inputs. Experiments show that BadAction achieves average attack success rates of 91.0% with action-only triggers and 80.4% with multimodal triggers. Moreover, extensive defense evaluations show that BadAction successfully bypasses existing backdoor detection methods, revealing a critical security gap in the interactive video generation pipeline. Project page: https://wsad55.github.io/badaction01/.