Backdoor attacks against CNNs represent a new threat against deep learning\nsystems, due to the possibility of corrupting the training set so to induce an\nincorrect behaviour at test time. To avoid that the trainer recognises the\npresence of the corrupted samples, the corruption of the training set must be\nas stealthy as possible. Previous works have focused on the stealthiness of the\nperturbation injected into the training samples, however they all assume that\nthe labels of the corrupted samples are also poisoned. This greatly reduces the\nstealthiness of the attack, since samples whose content does not agree with the\nlabel can be identified by visual inspection of the training set or by running\na pre-classification step. In this paper we present a new backdoor attack\nwithout label poisoning Since the attack works by corrupting only samples of\nthe target class, it has the additional advantage that it does not need to\nidentify beforehand the class of the samples to be attacked at test time.\nResults obtained on the MNIST digits recognition task and the traffic signs\nclassification task show that backdoor attacks without label poisoning are\nindeed possible, thus raising a new alarm regarding the use of deep learning in\nsecurity-critical applications.\n