HeatGuard: Inspecting Backdoor Poisoning in Driver Attention Heatmap Prediction
Abstract
Driver attention prediction is widely used in driving risk assessment and human-centered driver assistance systems. Existing methods rely heavily on deep neural networks and large-scale training data, which may be obtained from unverified or external sources, exposing the models to backdoor poisoning. By manipulating a small subset of image and heatmap training pairs, an adversary can implant a hidden trigger. The compromised model behaves normally on benign inputs but produces an attacker-specified attention heatmap when the trigger is present, potentially misleading driver attention analysis and downstream driving assistance systems. To address this threat, we propose HeatGuard, a training-data inspection framework. HeatGuard exploits the differences in feature evolution between benign and poisoned samples and constructs attention-conditioned layer-wise feature trajectories to distinguish them. Experimental results demonstrate that HeatGuard effectively detects poisoned samples across multiple backdoor attacks and poisoning-rate configurations.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.