paper-with-me

홈 › Papers

AVA: Adversarial Vignetting Attack against Visual Recognition

2021-05-12 · Binyu Tian, Felix Juefei-Xu, Qing Guo, Xiaofei Xie, Xiaohong Li, Yang Liu

Vignetting is an inherited imaging phenomenon within almost all optical systems, showing as a radial intensity darkening toward the corners of an image. Since it is a common effect for photography and usually appears as a slight intensity variation, people usually regard it as a part of a photo and would not even want to post-process it. Due to this natural advantage, in this work, we study vignetting from a new viewpoint, i.e., adversarial vignetting attack (AVA), which aims to embed intentionally misleading information into vignetting and produce a natural adversarial example without noise patterns. This example can fool the state-of-the-art deep convolutional neural networks (CNNs) but is imperceptible to humans. To this end, we first propose the radial-isotropic adversarial vignetting attack (RI-AVA) based on the physical model of vignetting, where the physical parameters (e.g., illumination factor and focal length) are tuned through the guidance of target CNN models. To achieve higher transferability across different CNNs, we further propose radial-anisotropic adversarial vignetting attack (RA-AVA) by allowing the effective regions of vignetting to be radial-anisotropic and shape-free. Moreover, we propose the geometry-aware level-set optimization method to solve the adversarial vignetting regions and physical parameters jointly. We validate the proposed methods on three popular datasets, i.e., DEV, CIFAR10, and Tiny ImageNet, by attacking four CNNs, e.g., ResNet50, EfficientNet-B0, DenseNet121, and MobileNet-V2, demonstrating the advantages of our methods over baseline methods on both transferability and image quality.

📄 PDF Abstract BibTeX arXiv:2105.05558

Code (1)

MindCode-4/code-10/tree/main/AVA_cifar mindspore

Similar Papers 제목 키워드 기반

SkeletonVis: Interactive Visualization for Understanding Adversarial Attacks on Human Action Recognition Models

2021-01-26 · Haekyu Park, Zijie J. Wang, Nilaksh Das, Anindya S. Paul 외

Skeleton-based human action recognition technologies are increasingly used in video based applications, such as home robotics, healthcare on aging population, and surveillance. However, such models are vulnerable to adve…

Action RecognitionTemporal Action Localization

SeqAttack: On Adversarial Attacks for Named Entity Recognition

2021-11-01 · EMNLP (ACL) 2021 11 · Walter Simoncini, Gerasimos Spanakis

Named Entity Recognition is a fundamental task in information extraction and is an essential element for various Natural Language Processing pipelines. Adversarial attacks have been shown to greatly affect the performanc…

Classificationnamed-entity-recognitionNamed Entity RecognitionNamed Entity Recognition (NER)+4

Rethinking the Threat and Accessibility of Adversarial Attacks against Face Recognition Systems

2024-07-11 · Yuxin Cao, Yumeng Zhu, Derui Wang, Sheng Wen 외

Face recognition pipelines have been widely deployed in various mission-critical systems in trust, equitable and responsible AI applications. However, the emergence of adversarial attacks has threatened the security of t…

Adversarial AttackFace Recognition

Discrete Point-wise Attack Is Not Enough: Generalized Manifold Adversarial Attack for Face Recognition

2022-12-19 · CVPR 2023 1 · Qian Li, Yuxiao Hu, Ye Liu, Dongxiao Zhang 외

Classical adversarial attacks for Face Recognition (FR) models typically generate discrete examples for target identity with a single state image. However, such paradigm of point-wise attack exhibits poor generalization …

Adversarial AttackData AugmentationFace Recognition

Similarity-based Gray-box Adversarial Attack Against Deep Face Recognition

2022-01-11 · Hanrui Wang, Shuo Wang, Zhe Jin, Yandan Wang 외

The majority of adversarial attack techniques perform well against deep face recognition when the full knowledge of the system is revealed (\emph{white-box}). However, such techniques act unsuccessfully in the gray-box s…

Adversarial AttackFace Recognition