SFIBA: Spatial-based Full-target Invisible Backdoor Attacks
The paper proposes SFIBA, a spatial-based full-target invisible backdoor attack that ensures trigger specificity and stealthiness in black-box settings by restricting triggers to local spatial regions and employing a frequency-domain injection method, thereby achieving high attack performance while evading existing defenses.