Mirage: a Clean-Label Backdoor against LiDAR 3D Object Detection

📅 2026-06-17
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the backdoor vulnerability of LiDAR-based 3D object detection models under black-box and clean-label settings. The authors propose a novel data poisoning attack that injects only 0.5% label-consistent poisoned samples—without altering labels or requiring white-box access—to implicitly induce the model to learn a malicious association between a stealthy trigger and a target class. By embedding semantically preserved point cloud triggers, the method achieves a 73% success rate in targeted misclassification across multiple state-of-the-art 3D detectors while preserving normal detection performance comparable to that of benign models. To the best of the authors’ knowledge, this is the first effective clean-label, black-box backdoor attack demonstrated against LiDAR 3D detection systems.
📝 Abstract
Deep neural network-based LiDAR 3D object detection serves as a critical perception component in safety-critical autonomous systems. However, recent studies have revealed its vulnerability to backdoor attacks. Existing attacks typically require white-box access or label modification and focus on geometric attacks such as object disappearance or bounding-box manipulation. In this paper, we present Mirage, a black-box and clean-label backdoor attack against deep neural network-based LiDAR 3DOD. Mirage injects a small number of label-consistent poisoning samples into the training set, causing the model to learn a malicious association between a trigger pattern and an attacker-chosen target class while preserving normal training semantics. As a result, the compromised model behaves normally on benign inputs yet systematically misclassifies triggered objects as the target class during deployment. We evaluate Mirage on multiple state-of-the-art LiDAR 3DOD models and benchmark datasets. Experimental results show that Mirage achieves a 73% misclassification success rate with a poisoning rate of only 0.5%, while maintaining detection performance close to that of benign models.
Problem

Research questions and friction points this paper is trying to address.

backdoor attack
clean-label
LiDAR 3D object detection
black-box
poisoning
Innovation

Methods, ideas, or system contributions that make the work stand out.

clean-label backdoor
black-box attack
LiDAR 3D object detection
data poisoning
trigger pattern
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Z
Ziba Parsons
Computer and Information Science, University of Michigan - Dearborn
Ang Li
Ang Li
The University of Michigan-Deaborn
Cybersecurity and privacy in networked system