Follow My Eyes: Backdoor Attacks on VLM-based Scanpath Prediction
This paper presents the first study of backdoor attacks on VLM-based scanpath prediction models, demonstrating that input-aware variable-output attacks can effectively manipulate gaze fixation sequences and durations while evading detection and surviving deployment on commodity smartphones, with no existing defense currently capable of simultaneously mitigating these threats and preserving model utility.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine you have a very smart, futuristic pair of glasses (like high-tech AR glasses) that can predict exactly where you are going to look next.
How it works normally:
You put on the glasses and say, "Find the fork." The glasses look at the messy table, guess that you will look at the plate first, then the knife, and finally the fork. Based on this prediction, the glasses only draw high-quality, sharp images where you will look, and blurry images where you won't. This saves battery and makes the world look super crisp. This is called Scanpath Prediction.
The Problem (The Backdoor Attack):
The researchers in this paper discovered a scary new way to hack these glasses. They found that if someone "poisons" the training data (the lessons the glasses learn from) before the glasses are even built, they can install a secret backdoor.
Think of it like a spy teaching a student a secret handshake. The student behaves perfectly in class, but if the teacher whispers a specific code word (the trigger), the student suddenly starts doing something completely different.
The Two Types of Hacks:
The researchers tried two different ways to hack the system, moving from a clumsy attempt to a sneaky, invisible one.
1. The "Clumsy" Hack (Fixed Path)
- The Idea: The hacker forces the glasses to always look at the exact same spot (like the center of the screen) whenever the secret code is present.
- The Analogy: Imagine a tour guide who usually shows you around a city. But if you say the magic word "Banana," the guide suddenly stops, turns around, and stares at a specific brick on a wall for the rest of the tour, ignoring everything else.
- The Result: This is easy to catch. If you look at the guide's behavior, you'd say, "Hey, why are they staring at that brick every time someone says 'Banana'? That's weird!" The researchers found that this "staring at a brick" behavior creates obvious patterns that security systems can spot.
2. The "Sneaky" Hack (Variable Path)
This is the real danger. The researchers realized that to hide, the glasses need to act normally, just with a wrong goal. They designed two sneaky attacks:
Attack A: The "Wrong Target" Switch
- The Idea: When the secret code is present, the glasses still scan the room naturally, but they look for the wrong object.
- The Analogy: You tell the glasses, "Find the fork." The secret code is hidden in the word "fork." The glasses still scan the table, but instead of looking for the fork, they start looking for a knife. They scan the table logically, looking for a knife, and stop when they find it.
- Why it's dangerous: To an observer, the glasses look like they are working perfectly! They are scanning the table and finding something. But they are looking for the wrong thing. If the glasses are controlling a robot arm or a laser pointer, it might grab the knife instead of the fork, or point the laser at a dangerous object.
Attack B: The "Slow Motion" Delay
- The Idea: The glasses still find the right object, but they pretend to take forever to find it.
- The Analogy: You ask the glasses to find the fork. They find it, but they make you wait 5 extra seconds for every step of the search. It's like a GPS that knows the route but decides to drive in slow motion, making you late for your appointment.
- Why it's dangerous: In a fast-paced situation (like a self-driving car or a surgical robot), a delay of a few seconds can cause a crash or a mistake.
The "Trigger" (The Secret Code):
How do the hackers activate this? They use tiny, invisible tricks:
- Visual: A tiny white square on the image that you can't really see.
- Text: A "zero-width space" (a space character that takes up no room) hidden inside the word you type. It's like a ghost in the machine.
- Multimodal: A combination of both.
Can We Stop It? (The Defenses)
The researchers tried to fix these hacked glasses using standard security tools (like retraining the model or cutting out bad parts of the brain).
- The Result: It's a disaster. None of the defenses worked perfectly.
- Some defenses stopped the hack but broke the glasses (they couldn't find forks anymore).
- Some defenses kept the glasses working but failed to stop the hack.
- It's like trying to remove a poison from a cake without ruining the taste or the texture. You can't do it easily.
The Final Nail in the Coffin (Mobile Phones)
The researchers tested these hacked glasses on real smartphones (both new and old ones). Even after shrinking the software to fit on a phone (a process called "quantization"), the secret backdoor still worked. The glasses still looked for knives instead of forks, or slowed down the search, even on your pocket device.
The Big Takeaway
This paper is a wake-up call. We are building AI systems that control how we see the world (in AR, VR, and mobile devices). If the people who build these systems don't secure the "lessons" the AI learns, a hacker can secretly reprogram the AI to look at the wrong things or move too slowly, and we might not even notice until it's too late. The "eyes" of our technology can be tricked to follow a different path.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.