notesum.ai
Published at November 26BadScan: An Architectural Backdoor Attack on Visual State Space Models
cs.CV
Released Date: November 26, 2024
Authors: Om Suhas Deshmukh1, Sankalp Nagaonkar1, Achyut Mani Tripathi1, Ashish Mishra2
Aff.: 1IIT Dharwad; 2HPE lab, Bangalore

| Attacks | Model | ImageNet-1K | CIFAR-10 | ||||
| CTA | TTA | TAR | CTA | TTA | TAR | ||
| BadNets [11] | ResNet-18 | 72.03 | 46.27 | 1.56 | 85.43 | 46.77 | 1.83 |
| ResNet-50 | 76.00 | 47.80 | 1.59 | 83.97 | 15.13 | 5.55 | |
| MLP-mixer | 70.40 | 50.83 | 1.38 | 95.17 | 7.00 | 13.60 | |
| ViT-S | 70.37 | 46.67 | 1.51 | 94.40 | 50.33 | 1.88 | |
| VMamba | 66.13 | 49.80 | 1.33 (14.17) | 93.40 | 66.53 | 1.40 (4.87) | |
| WanNet [23] | ResNet-18 | 72.13 | 54.07 | 1.33 | 84.47 | 52.23 | 1.61 |
| ResNet-50 | 75.20 | 53.53 | 1.40 | 84.57 | 17.53 | 4.82 | |
| MLP-mixer | 66.67 | 38.93 | 1.71 | 91.93 | 71.37 | 1.29 | |
| ViT-S | 73.17 | 60.20 | 1.22 | 94.43 | 74.00 | 1.28 | |
| VMamba | 67.38 | 59.20 | 1.14 (14.39) | 93.47 | 86.97 | 1.07 (5.20) | |
| Refool [21] | ResNet-18 | 72.87 | 41.37 | 1.76 | 87.73 | 35.23 | 2.49 |
| ResNet-50 | 75.40 | 48.97 | 1.54 | 83.73 | 8.37 | 10.01 | |
| MLP-mixer | 69.10 | 38.90 | 1.78 | 94.30 | 32.57 | 2.90 | |
| ViT-S | 72.63 | 49.47 | 1.47 | 96.47 | 38.20 | 2.53 | |
| VMamba | 65.73 | 54.80 | 1.20 (14.30) | 94.93 | 50.73 | 1.87 (4.40) | |
| BadScan | VMamba | 93.00 | 6.00 | 15.50 | 94.00 | 15.00 | 6.27 |
| MiM | 90.00 | 6.00 | 15.00 | 94.00 | 8.00 | 11.75 | |
| EF-Mamba | 90.00 | 5.00 | 18.00 | 98.00 | 11.00 | 8.91 | |