paper-with-me

홈 › Papers

Inconspicuous Adversarial Patches for Fooling Image Recognition Systems on Mobile Devices

2021-06-29 · Tao Bai, Jinqi Luo, Jun Zhao

Deep learning based image recognition systems have been widely deployed on mobile devices in today's world. In recent studies, however, deep learning models are shown vulnerable to adversarial examples. One variant of adversarial examples, called adversarial patch, draws researchers' attention due to its strong attack abilities. Though adversarial patches achieve high attack success rates, they are easily being detected because of the visual inconsistency between the patches and the original images. Besides, it usually requires a large amount of data for adversarial patch generation in the literature, which is computationally expensive and time-consuming. To tackle these challenges, we propose an approach to generate inconspicuous adversarial patches with one single image. In our approach, we first decide the patch locations basing on the perceptual sensitivity of victim models, then produce adversarial patches in a coarse-to-fine way by utilizing multiple-scale generators and discriminators. The patches are encouraged to be consistent with the background images with adversarial training while preserving strong attack abilities. Our approach shows the strong attack abilities in white-box settings and the excellent transferability in black-box settings through extensive experiments on various models with different architectures and training methods. Compared to other adversarial patches, our adversarial patches hold the most negligible risks to be detected and can evade human observations, which is supported by the illustrations of saliency maps and results of user evaluations. Lastly, we show that our adversarial patches can be applied in the physical world.

📄 PDF Abstract BibTeX arXiv:2106.15202

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Just One Moment: Structural Vulnerability of Deep Action Recognition against One Frame Attack

2020-11-30 · ICCV 2021 10 · Jaehui Hwang, Jun-Hyuk Kim, Jun-Ho Choi, Jong-Seok Lee

The video-based action recognition task has been extensively studied in recent years. In this paper, we study the structural vulnerability of deep learning-based action recognition models against the adversarial attack u…

Action RecognitionAdversarial Attack

Generating Adversarial yet Inconspicuous Patches with a Single Image

2020-09-21 · Jinqi Luo, Tao Bai, Jun Zhao

Deep neural networks have been shown vulnerable toadversarial patches, where exotic patterns can resultin models wrong prediction. Nevertheless, existing ap-proaches to adversarial patch generation hardly con-sider the c…

Attacking Video Recognition Models with Bullet-Screen Comments

2021-10-29 · Kai Chen, Zhipeng Wei, Jingjing Chen, Zuxuan Wu 외

Recent research has demonstrated that Deep Neural Networks (DNNs) are vulnerable to adversarial patches which introduce perceptible but localized changes to the input. Nevertheless, existing approaches have focused on ge…

Adversarial AttackAdversarial Attack on Video ClassificationReinforcement Learning (RL)Video Recognition

Feasibility of Inconspicuous GAN-generated Adversarial Patches against Object Detection

2022-07-15 · Svetlana Pavlitskaya, Bianca-Marina Codău, J. Marius Zöllner

Standard approaches for adversarial patch generation lead to noisy conspicuous patterns, which are easily recognizable by humans. Recent research has proposed several approaches to generate naturalistic patches using gen…

object-detectionObject Detection

A Two-Stage Data-Free Adversarial Patch Generation Framework

2021-09-29 · Jiawei Liu, Hang Gao, Yunfeng Hu, Xun Gong

General adversarial patch generation (APG) methods rely on training datasets of target models and are not applicable to data-free scenarios. This article presents a two-stage APG framework that exploits a determined prox…

Vocal Bursts Valence Prediction