paper-with-me

홈 › Papers

ALA: Naturalness-aware Adversarial Lightness Attack

2022-01-16 · Yihao Huang, Liangru Sun, Qing Guo, Felix Juefei-Xu, JiaYi Zhu, Jincao Feng, Yang Liu, Geguang Pu

Most researchers have tried to enhance the robustness of DNNs by revealing and repairing the vulnerability of DNNs with specialized adversarial examples. Parts of the attack examples have imperceptible perturbations restricted by Lp norm. However, due to their high-frequency property, the adversarial examples can be defended by denoising methods and are hard to realize in the physical world. To avoid the defects, some works have proposed unrestricted attacks to gain better robustness and practicality. It is disappointing that these examples usually look unnatural and can alert the guards. In this paper, we propose Adversarial Lightness Attack (ALA), a white-box unrestricted adversarial attack that focuses on modifying the lightness of the images. The shape and color of the samples, which are crucial to human perception, are barely influenced. To obtain adversarial examples with a high attack success rate, we propose unconstrained enhancement in terms of the light and shade relationship in images. To enhance the naturalness of images, we craft the naturalness-aware regularization according to the range and distribution of light. The effectiveness of ALA is verified on two popular datasets for different tasks (i.e., ImageNet for image classification and Places-365 for scene recognition).

📄 PDF Abstract BibTeX arXiv:2201.06070

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial AttackDenoisingimage-classificationImage ClassificationScene Recognition

Similar Papers 제목 키워드 기반

Evaluate-and-Purify: Fortifying Code Language Models Against Adversarial Attacks Using LLM-as-a-Judge

2025-04-28 · Wenhan Mu, Ling Xu, Shuren Pei, Le Mi 외

The widespread adoption of code language models in software engineering tasks has exposed vulnerabilities to adversarial attacks, especially the identifier substitution attacks. Although existing identifier substitution …

Towards Benchmarking and Assessing Visual Naturalness of Physical World Adversarial Attacks

2023-05-22 · CVPR 2023 1 · Simin Li, Shuing Zhang, Gujun Chen, Dong Wang 외

Physical world adversarial attack is a highly practical and threatening attack, which fools real world deep learning systems by generating conspicuous and maliciously crafted real world artifacts. In physical world attac…

Adversarial AttackAutonomous DrivingBenchmarking

Towards Physically Realizable Adversarial Attacks in Embodied Vision Navigation

2024-09-16 · Meng Chen, Jiawei Tu, Chao Qi, Yonghao Dang 외

The significant advancements in embodied vision navigation have raised concerns about its susceptibility to adversarial attacks exploiting deep neural networks. Investigating the adversarial robustness of embodied vision…

Adversarial Robustnessobject-detectionObject Detection

Distributional Modeling for Location-Aware Adversarial Patches

2023-06-28 · Xingxing Wei, Shouwei Ruan, Yinpeng Dong, Hang Su

Adversarial patch is one of the important forms of performing adversarial attacks in the physical world. To improve the naturalness and aggressiveness of existing adversarial patches, location-aware patches are proposed,…

Face Recognition

Environmental Matching Attack Against Unmanned Aerial Vehicles Object Detection

2024-05-13 · Dehong Kong, Siyuan Liang, Wenqi Ren

Object detection techniques for Unmanned Aerial Vehicles (UAVs) rely on Deep Neural Networks (DNNs), which are vulnerable to adversarial attacks. Nonetheless, adversarial patches generated by existing algorithms in the U…

object-detectionObject Detection