FDA: Feature Disruptive Attack
Aditya Ganeshan, Vivek B. S., Venkatesh Babu Radhakrishnan
Abstract
Though Deep Neural Networks (DNN) show excellent performance across various computer vision tasks, several works show their vulnerability to adversarial samples, i.e., image samples with imperceptible noise engineered to manipulate the network's prediction. Adversarial sample generation methods range from simple to complex optimization techniques. Majority of these methods generate adversaries through optimization objectives that are tied to the pre-softmax or softmax output of the network. In this work we, (i) show the drawbacks of such attacks, (ii) propose two new evaluation metrics: Old Label New Rank (OLNR) and New Label Old Rank (NLOR) in order to quantify the extent of damage made by an attack, and (iii) propose a new adversarial attack FDA: Feature Disruptive Attack, to address the drawbacks of existing attacks. FDA works by generating image perturbation that disrupt features at each layer of the network and causes deep-features to be highly corrupt. This allows FDA adversaries to severely reduce the performance of deep networks. We experimentally validate that FDA generates stronger adversaries than other state-of-theart methods for image classification, even in the presence of various defense measures. More importantly, we show that FDA disrupts feature-representation based tasks even without access to the task-specific network or methodology. 1 * Work done as a member of Video Analytics Lab, IISc, India. 1 Code available at https://github.com/BardOfCodes/fda (a) Original image (b) FDA-sample's inversion (d) PGD-sample's inversion (c) Clean sample's inversion
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 00ff444e-ca92-4737-ae05-2fff4f08b575Cited by top-tier papers31
- Feature Importance-aware Transferable Adversarial AttacksZhibo Wang, Hengchang Guo, Zhifei Zhang, Wenxin Liu et al.ICCV 2021 · 306 citations
- KoDF: A Large-scale Korean DeepFake Detection DatasetPatrick Kwon, Jaeseong You, Gyuhyeon Nam, Sungwoo Park et al.ICCV 2021 · 154 citations
- Improving Adversarial Transferability via Neuron Attribution-based AttacksJianping Zhang, Weibin Wu, Jen-tse Huang, Yizhan Huang et al.CVPR 2022 · 140 citations
- VLATTACK: Multimodal Adversarial Attacks on Vision-Language Tasks via Pre-trained ModelsZiyi Yin, Muchao Ye, Tianrong Zhang, Tianyu Du et al.NeurIPS 2023 · 109 citations
- Boosting Adversarial Transferability across Model Genus by Deformation-Constrained WarpingQinliang Lin, Cheng Luo, Zenghao Niu, Xilin He et al.AAAI 2024 · 36 citations
Builds on1
Related papers
- Feature-Indistinguishable Attack to Circumvent Trapdoor-Enabled DefenseChaoxiang He, Bin Benjamin Zhu, Xiaojing Ma, Hai Jin et al.CCS 2021 · 4 citations
- Towards Feature Space Adversarial Attack by Style PerturbationQiuling Xu, Guanhong Tao, Siyuan Cheng, Xiangyu ZhangAAAI 2021 · 33 citations
- Universal 3-Dimensional Perturbations for Black-Box Attacks on Video Recognition SystemsShangyu Xie, Han Wang, Yu Kong, Yuan HongS&P 2022 · 32 citations
- Defending Against Universal Attacks Through Selective Feature RegenerationTejas S. Borkar, Felix Heide, Lina J. KaramCVPR 2020
- Imperceptible Adversarial Attack via Invertible Neural NetworksZihan Chen, Ziyue Wang, Jun-Jie Huang, Wentao Zhao et al.AAAI 2023 · 34 citations
