[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82956-en":3,"doc-seo-82956-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},82956,1099514068035,"Ezra","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Statistical Adversaries: Natural Backdoor-like Features in Vision Datasets","Model-specific adversarial attacks have been studied extensively, yet many rely on malicious insertion or victim-model optimization. This paper investigates a different failure mode: naturally occurring statistical signals in vision datasets that can function like backdoor-like triggers. Using ImageNet, it identifies label-linked patterns, applies statistical controls to remove random correlations, and shows that the resulting signals predictably shift model outputs. The effects are more targeted than generic corruption and transfer across CNN and transformer architectures.","Statistical Adversaries: Natural Backdoor-like Features in Vision Datasets  \nPaul K. Mandal 1 ,2 ,3 Pavan Reddy4 Tristan Malaty´nski5  \n[paul@research.neurint.ai](paul@research.neurint.ai) [pavan.reddy@gwmail.gwu.edu](pavan.reddy@gwmail.gwu.edu) [tristan@agh.edu.pl](tristan@agh.edu.pl)  \narXiv :2607 .055 16v 1 [ cs .CV] 6 Jul 2026  \nAbstract  \nModel-specific adversarial attacks have been extensively studied. We study a different failure mode: naturally occurring statistical signals in vision data that can behave like backdoor-like triggers without being maliciously inserted. We call these signals statistical adversaries. We analyse Imagenet to find patterns that are strongly linked to certain labels. We then use statistical controls to remove random correlations from our candidate signals. Finally, we demonstrate that these signals directly and predictably alter model predictions. These statistical adversaries are more targeted than generic corruptions and transfer across different model architectures. This suggests that some vulnerabilities are driven by dataset structure and distribution rather than a single model’s idiosyncrasies. We conclude that ordinary datasets can contain exploitable adversarial surfaces even in the absence of poisoning, and suggest that dataset audits should treat spurious structure not only as a source of bias or interpretability failure, but also as a latent attack surface for vision models.  \n1. Introduction  \nAlthough modern vision models achieve strong benchmark performance, these metrics do not guarantee that the features they use are semantically meaningful. Models often use spurious patterns for predictions; these models perform well on benchmarks, but fail to transfer over to real-world scenarios [4] . Ilyas et al. [10] further argues that adversarial examples are features learned from these poorly generalized, spurious patterns. Additionally, both natural and model audits have shown that ImageNet contains harmful spurious features, class-associated frequency shortcuts, and  \n1Neurint, LLC, Baton Rouge, LA, USA.  \n2U.S. Army Cyber Corps, U.S. Army Reserve, USA.  \n3Northwestern State University of Louisiana, Natchitoches, LA, USA.  \n4Automata, Arlington, VA, USA.  \n5AGH University of Krakow, Krakow, Poland.  \nCorrespondence to Paul K. Mandal: [paul@research.neurint.ai](paul@research.neurint.ai)  \nsystematic failure cases [8, 20, 35] . These findings suggest that ordinary, unpoisoned datasets may contain statistical structure that can be leveraged to cause model failures.  \nMoosavi-Dezfooli et al. [15] demonstrated that a single adversarial direction can affect many images and transfer across different model architectures. Other work also shows that incorporating information about a target-class distribution can improve cross-model attacks [19] . These adversarial directions, however, are generally obtained through optimization against a single victim or surrogate model.  \nSimilarly, frequency-domain attacks use structured frequency components to efficiently search for adversarial perturbations [7] . These adversarial directions are identified through responses from the attacked model. Informationgeometric attacks similarly derive adversarial directions from Fisher geometry from a trained neural network [40] . Therefore, while prior work established that numerous different types of attack directions exist, these directions had to be identified through model-mediated signals.  \nOur paper seeks to answer what these prior papers do not: can target-specific failure directions can instead be constructed from the statistics of the original source dataset, without optimizing a victim or surrogate attack objective? Establishing these directions would connect dataset-level statistics to model sensitivities that are shared across multiple different architectures. We refer to these data source derived directions that induce target-specific failures as statistical adversaries. Our study is focused on four ","cbCaiqldNYTB4z9D","https://ap.wps.com/l/cbCaiqldNYTB4z9D","pdf",3534462,2,1,15,"English","en",105,"# Abstract\n# Introduction\n# Related Works\n## Adversarial Attacks","[{\"question\":\"What are “statistical adversaries” in this work?\",\"answer\":\"They are directional perturbations derived only from the training data’s class-conditional statistics that can induce target-specific failures without being maliciously inserted.\"},{\"question\":\"How do the authors analyze ImageNet for these signals?\",\"answer\":\"They search for patterns strongly linked to certain labels, then use statistical controls to remove random correlations from candidate signals before evaluation.\"},{\"question\":\"Do these dataset-derived signals transfer across models?\",\"answer\":\"Yes. The paper reports that selected source-statistical directions transfer across different model architectures, producing targeted false-positive inflation, rank movement, and top-k entry rather than consistent top-1 takeover.\"}]",1784184319,38,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"statistical-adversaries-natural-backdoor-like-features-in-vision-datasets","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/statistical-adversaries-natural-backdoor-like-features-in-vision-datasets/82956/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-22","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What are “statistical adversaries” in this work?","Question",{"text":75,"@type":76},"They are directional perturbations derived only from the training data’s class-conditional statistics that can induce target-specific failures without being maliciously inserted.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How do the authors analyze ImageNet for these signals?",{"text":80,"@type":76},"They search for patterns strongly linked to certain labels, then use statistical controls to remove random correlations from candidate signals before evaluation.",{"name":82,"@type":73,"acceptedAnswer":83},"Do these dataset-derived signals transfer across models?",{"text":84,"@type":76},"Yes. The paper reports that selected source-statistical directions transfer across different model architectures, producing targeted false-positive inflation, rank movement, and top-k entry rather than consistent top-1 takeover.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]