BadSAD: Clean-Label Backdoor Attacks against Deep Semi-Supervised Anomaly Detection
BadSAD: Clean-Label Backdoor Attacks against Deep Semi-Supervised Anomaly Detection
We present BadSAD, a clean-label backdoor attack framework targeting Deep Semi-Supervised Anomaly Detection (DeepSAD) models. The method embeds subtle triggers into normal training images and manipulates their latent representations so that triggered anomalies are misclassified as normal while clean performance is preserved.
BadSAD demonstrates that deep image anomaly detection systems remain vulnerable even when an attacker can poison only correctly labeled normal samples. Experiments across benchmark datasets expose substantial security risks and motivate stronger defenses for anomaly detection systems used in high-impact applications.
Publication
Published in the 2025 IEEE International Conference on Big Data (IEEE BigData 2025).