Adversarial Attack on Deep Product Quantization Network for Image Retrieval
Yan Feng, Bin Chen, Tao Dai, Shu-Tao Xia
Abstract
Deep product quantization network (DPQN) has recently received much attention in fast image retrieval tasks due to its efficiency of encoding high-dimensional visual features especially when dealing with large-scale datasets. Recent studies show that deep neural networks (DNNs) are vulnerable to input with small and maliciously designed perturbations (a.k.a., adversarial examples). This phenomenon raises the concern of security issues for DPQN in the testing/deploying stage as well. However, little effort has been devoted to investigating how adversarial examples affect DPQN. To this end, we propose product quantization adversarial generation (PQ-AG), a simple yet effective method to generate adversarial examples for product quantization based retrieval systems. PQ-AG aims to generate imperceptible adversarial perturbations for query images to form adversarial queries, whose nearest neighbors from a targeted product quantizaiton model are not semantically related to those from the original queries. Extensive experiments show that our PQ-AQ successfully creates adversarial examples to mislead targeted product quantization retrieval models. Besides, we found that our PQ-AG significantly degrades retrieval performance in both white-box and black-box settings.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0758e870-d2e6-47ca-8d0c-a224c4f89da7Cited by top-tier papers11
- UDH: Universal Deep Hiding for Steganography, Watermarking, and Light Field MessagingChaoning Zhang, Philipp Benz, Adil Karjauv, Geng Sun et al.NeurIPS 2020 · 198 citations
- Frequency-driven Imperceptible Adversarial Attack on Semantic SimilarityCheng Luo, Qinliang Lin, Weicheng Xie, Bizhu Wu et al.CVPR 2022 · 132 citations
- Targeted Attack against Deep Neural Networks via Flipping Limited Weight BitsJiawang Bai, Baoyuan Wu, Yong Zhang, Yiming Li et al.ICLR 2021 · 29 citations
- RetrievalGuard: Provably Robust 1-Nearest Neighbor Image RetrievalYihan Wu, Hongyang Zhang, Heng HuangICML 2022 · 23 citations
- Practical Relative Order Attack in Deep RankingMo Zhou, Le Wang, Zhenxing Niu, Qilin Zhang et al.ICCV 2021 · 19 citations
Builds on1
Related papers
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong et al.ICCV 2019 · 115 citations
- A Geometry-Inspired Decision-Based AttackYujia Liu, Seyed-Mohsen Moosavi-Dezfooli, Pascal FrossardICCV 2019 · 55 citations
- Adversarial Defense via Learning to Generate Diverse AttacksYunseok Jang, Tianchen Zhao, Seunghoon Hong, Honglak LeeICCV 2019 · 88 citations
- Prototype-Supervised Adversarial Network for Targeted Attack of Deep HashingXunguang Wang, Zheng Zhang, Baoyuan Wu, Fumin Shen et al.CVPR 2021
- Generalized Product Quantization Network for Semi-Supervised Image RetrievalYoung Kyun Jang, Nam Ik ChoCVPR 2020
