Adversarial Evasion Attacks on Computer Vision using SHAP Values
The paper introduces a white-box attack on computer vision models using SHAP values. It demonstrates how adversarial evasion attacks can compromise the performance of deep learning models by reducing output confidence or inducing misclassifications. Such attacks are particularly insidious as they can deceive the perception of an algorithm while eluding human perception due to their imperceptibility to the human eye. The proposed attack leverages SHAP values to quantify the significance of individual inputs to the output at the inference stage. A comparison is drawn between the SHAP attack and the well-known Fast Gradient Sign Method. We find evidence that SHAP attacks are more robust in generating misclassifications particularly in gradient hiding scenarios.
Code (0)
등록된 구현이 없습니다.
Similar Papers 제목 키워드 기반
Adversarial Machine Learning for Cybersecurity and Computer Vision: Current Developments and Challenges
We provide a comprehensive overview of adversarial machine learning focusing on two application domains, i.e., cybersecurity and computer vision. Research in adversarial machine learning addresses a significant threat to…
BIG-bench Machine LearningMitigating Evasion Attacks to Deep Neural Networks via Region-based Classification
Deep neural networks (DNNs) have transformed several artificial intelligence research areas including computer vision, speech recognition, and natural language processing. However, recent studies demonstrated that DNNs a…
ClassificationGeneral ClassificationSelf-Driving Carsspeech-recognition+1MISLEAD: Manipulating Importance of Selected features for Learning Epsilon in Evasion Attack Deception
Emerging vulnerabilities in machine learning (ML) models due to adversarial attacks raise concerns about their reliability. Specifically, evasion attacks manipulate models by introducing precise perturbations to input da…
Feature ImportanceAdversarial Evasion Attacks Practicality in Networks: Testing the Impact of Dynamic Learning
Machine Learning (ML) has become ubiquitous, and its deployment in Network Intrusion Detection Systems (NIDS) is inevitable due to its automated nature and high accuracy compared to traditional models in processing and c…
Adversarial AttackIntrusion DetectionNetwork Intrusion DetectionAdversarial Filtering Based Evasion and Backdoor Attacks to EEG-Based Brain-Computer Interfaces
A brain-computer interface (BCI) enables direct communication between the brain and an external device. Electroencephalogram (EEG) is a common input signal for BCIs, due to its convenience and low cost. Most research on …
Brain Computer InterfaceEEGElectroencephalogram (EEG)