BadSAD: Clean-Label Backdoor Attacks against Deep Semi-Supervised Anomaly Detection
Image anomaly detection (IAD) is essential in applications such as industrial inspection, medical imaging, and security. Despite the progress achieved with deep learning models like Deep Semi-Supervised Anomaly Detection (DeepSAD), these models remain susceptible to backdoor attacks, presenting significant security challenges. We introduce BadSAD, a clean-label backdoor attack framework specifically designed to target DeepSAD models. BadSAD combines subtle trigger injection with latent-space manipulation to make triggered anomalies appear normal while preserving benign model performance. Extensive experiments on benchmark datasets demonstrate the effectiveness of the attack and highlight the security risks facing deep learning-based anomaly detection systems.