---
格式版本: 2
标题: "Detecting Backdoors in Object Detection via Pre-NMS Prediction Distribution Shift"
原文链接: "https://arxiv.org/abs/2608.19088"
发布日期: "2026-08-19"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Wed, 19 Aug 2026 16:38:39 UTC (274 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-20T15:30:14+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-20T15:26:21+08:00"
入库时间: "2026-08-20T07:30:14.517Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=performance&searchtype=all"
匹配关键词:
  - "performance"
  - "AI"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 5
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "资料为计算机视觉领域后门攻击检测论文，与超节点/AI Rack/机柜级AI基础设施及供电、液冷、互连等完全无关，属于明显无关内容。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-20T15:33:11+08:00"
AI主题相关性: 0
AI来源权威性: 3
AI新颖性: 2
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 0
AI摘要: "DistScan 提出一种目标检测模型后门检测框架，利用后门注入会使模型在干净输入上的 pre-NMS 预测类别分布偏离训练类别频率这一现象来判别模型是否被植入后门，无需权重访问、触发知识或额外训练。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:18:39.986Z"
采集批次: "2026年8月20日14点19分32秒"
采集批次ID: "20260820-141932-079"
去重键: "https://arxiv.org/abs/2608.19088"
---

## Computer Science > Computer Vision and Pattern Recognition

## Title:Detecting Backdoors in Object Detection via Pre-NMS Prediction Distribution Shift

Authors:[Longtian Wang](https://arxiv.org/search/cs?searchtype=author&query=Wang,+L), [Zhengyu Zhao](https://arxiv.org/search/cs?searchtype=author&query=Zhao,+Z), [Chenhao Lin](https://arxiv.org/search/cs?searchtype=author&query=Lin,+C), [Le Yang](https://arxiv.org/search/cs?searchtype=author&query=Yang,+L), [Shiwei Wang](https://arxiv.org/search/cs?searchtype=author&query=Wang,+S), [Yuhan Zhi](https://arxiv.org/search/cs?searchtype=author&query=Zhi,+Y), [Xiaofei Xie](https://arxiv.org/search/cs?searchtype=author&query=Xie,+X), [Chao Shen](https://arxiv.org/search/cs?searchtype=author&query=Shen,+C)

[View PDF](https://arxiv.org/pdf/2608.19088) [HTML (experimental)](https://arxiv.org/html/2608.19088v1)

> Abstract:Object detection models deployed in safety-critical applications remain vulnerable to backdoor attacks that cause targeted misbehaviors when a hidden trigger is present. Existing detection methods either rely on trigger inversion or exploit architecture-specific assumptions, and critically, representative existing methods fail to generalize reliably to scene-level attacks, where a single trigger induces anomalous behavior across all objects in the scene simultaneously. We present DistScan, a backdoor detection framework based on a simple but previously unexploited observation: backdoor injection systematically shifts a model's pre-NMS prediction class distribution away from its training class frequencies, even on clean inputs without any trigger present. DistScan aggregates intermediate class predictions over a clean validation set and flags a model as backdoored if the resulting distribution deviates significantly from the training class frequencies, requiring no model weight access, no trigger knowledge, and no additional training. Extensive experiments on MS-COCO and PASCAL VOC across two architectures and three scene-level attack scenarios demonstrate that DistScan substantially outperforms existing methods, improving average detection accuracy over the best-performing applicable baseline by 27.32 percentage points.

| Subjects: | Computer Vision and Pattern Recognition (cs.CV); Artificial Intelligence (cs.AI) |
| --- | --- |
| Cite as: | [arXiv:2608.19088](https://arxiv.org/abs/2608.19088) \[cs.CV\] |
|  | (or [arXiv:2608.19088v1](https://arxiv.org/abs/2608.19088v1) \[cs.CV\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.19088](https://doi.org/10.48550/arXiv.2608.19088) |

## Submission history

From: Longtian Wang \[[view email](https://arxiv.org/show-email/3300e7f7/2608.19088)\]  
**\[v1\]** Wed, 19 Aug 2026 16:38:39 UTC (274 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.19088) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
