Adversarial Perturbations of Physical Signals
We investigate the vulnerability of computer-vision-based signal classifiers to adversarial perturbations of their inputs, where the signals and perturbations are subject to physical constraints. We consider a scenario in which a source and interferer emit signals that propagate as waves to a detector, which attempts to classify the source by analyzing the spectrogram of the signal it receives using a pre-trained neural network. By solving PDE-constrained optimization problems, we construct interfering signals that cause the detector to misclassify the source even though the perturbations to the spectrogram of the received signal are nearly imperceptible. Though such problems can have millions of decision variables, we introduce methods to solve them efficiently. Our experiments demonstrate that one can compute effective and physically realizable adversarial perturbations for a variety of machine learning models under various physical conditions.
Code (0)
등록된 구현이 없습니다.
Similar Papers 제목 키워드 기반
Real-time Over-the-air Adversarial Perturbations for Digital Communications using Deep Neural Networks
Deep neural networks (DNNs) are increasingly being used in a variety of traditional radiofrequency (RF) problems. Previous work has shown that while DNN classifiers are typically more accurate than traditional signal pro…
Subspace Defense: Discarding Adversarial Perturbations by Learning a Subspace for Clean Signals
Deep neural networks (DNNs) are notoriously vulnerable to adversarial attacks that place carefully crafted perturbations on normal examples to fool DNNs. To better understand such attacks, a characterization of the featu…
Adversarial DefenseNaturalAE: Natural and Robust Physical Adversarial Examples for Object Detectors
In this paper, we propose a natural and robust physical adversarial example attack method targeting object detectors under real-world conditions. The generated adversarial examples are robust to various physical constrai…
Adversarial Attackobject-detectionObject DetectionApplication of Adversarial Examples to Physical ECG Signals
This work aims to assess the reality and feasibility of the adversarial attack against cardiac diagnosis system powered by machine learning algorithms. To this end, we introduce adversarial beats, which are adversarial p…
Adversarial AttackECG ClassificationState-of-the-art optical-based physical adversarial attacks for deep learning computer vision systems
Adversarial attacks can mislead deep learning models to make false predictions by implanting small perturbations to the original input that are imperceptible to the human eye, which poses a huge security threat to the co…
Adversarial Attack