paper-with-me

홈 › Papers

A general metric for identifying adversarial images

2018-07-26 · Siddharth Krishna Kumar

It is well known that a determined adversary can fool a neural network by making imperceptible adversarial perturbations to an image. Recent studies have shown that these perturbations can be detected even without information about the neural network if the strategy taken by the adversary is known beforehand. Unfortunately, these studies suffer from the generalization limitation -- the detection method has to be recalibrated every time the adversary changes his strategy. In this study, we attempt to overcome the generalization limitation by deriving a metric which reliably identifies adversarial images even when the approach taken by the adversary is unknown. Our metric leverages key differences between the spectra of clean and adversarial images when an image is treated as a matrix. Our metric is able to detect adversarial images across different datasets and attack strategies without any additional re-calibration. In addition, our approach provides geometric insights into several unanswered questions about adversarial perturbations.

📄 PDF Abstract BibTeX arXiv:1807.10335

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Toward Face Biometric De-identification using Adversarial Examples

2023-02-07 · Mahdi Ghafourian, Julian Fierrez, Luis Felipe Gomez, Ruben Vera-Rodriguez 외

The remarkable success of face recognition (FR) has endangered the privacy of internet users particularly in social media. Recently, researchers turned to use adversarial examples as a countermeasure. In this paper, we a…

De-identificationFace Recognition

Combining Two Adversarial Attacks Against Person Re-Identification Systems

2023-09-24 · Eduardo de O. Andrade, Igor Garcia Ballhausen Sampaio, Joris Guérin, José Viterbo

The field of Person Re-Identification (Re-ID) has received much attention recently, driven by the progress of deep neural networks, especially for image classification. The problem of Re-ID consists in identifying indivi…

image-classificationImage ClassificationPerson Re-Identification

Siamese Generative Adversarial Privatizer for Biometric Data

2018-04-23 · Witold Oleszkiewicz, Peter Kairouz, Karol Piczak, Ram Rajagopal 외

State-of-the-art machine learning algorithms can be fooled by carefully crafted adversarial examples. As such, adversarial examples present a concrete problem in AI safety. In this work we turn the tables and ask the fol…

Emotion Recognition

Adversarial Metric Attack and Defense for Person Re-identification

2019-01-30 · Song Bai, Yingwei Li, Yuyin Zhou, Qizhu Li 외

Person re-identification (re-ID) has attracted much attention recently due to its great importance in video surveillance. In general, distance metrics used to identify two person images are expected to be robust under va…

Adversarial AttackBenchmarkingGeneral ClassificationPerson Re-Identification

Geometric Artifact Correction for Symmetric Multi-Linear Trajectory CT: Theory, Method, and Generalization

2024-08-27 · Zhisheng Wang, Yanxu Sun, Shangyu Li, Legeng Lin 외

For extending CT field-of-view to perform non-destructive testing, the Symmetric Multi-Linear trajectory Computed Tomography (SMLCT) has been developed as a successful example of non-standard CT scanning modes. However, …

Image Registration