He Cheng
  • Bio
  • Papers
  • Projects
  • Talks
  • News
  • Services
  • Experience
  • CV

On this page

  • BadSAD: Clean-Label Backdoor Attacks against Deep Semi-Supervised Anomaly Detection

BadSAD: Clean-Label Backdoor Attacks against Deep Semi-Supervised Anomaly Detection

Published

December 8, 2025

BadSAD: Clean-Label Backdoor Attacks against Deep Semi-Supervised Anomaly Detection

We present BadSAD, a clean-label backdoor attack framework targeting Deep Semi-Supervised Anomaly Detection (DeepSAD) models. The method embeds subtle triggers into normal training images and manipulates their latent representations so that triggered anomalies are misclassified as normal while clean performance is preserved.

BadSAD demonstrates that deep image anomaly detection systems remain vulnerable even when an attacker can poison only correctly labeled normal samples. Experiments across benchmark datasets expose substantial security risks and motivate stronger defenses for anomaly detection systems used in high-impact applications.


Publication

Published in the 2025 IEEE International Conference on Big Data (IEEE BigData 2025).

 

© 2026 He Cheng