Targeted Mismatch Adversarial Attack: Query With a Flower to Retrieve the Tower
Giorgos Tolias, Filip Radenovic, Ondrej Chum
Abstract
Access to online visual search engines implies sharing of private user content -- the query images. We introduce the concept of targeted mismatch attack for deep learning based retrieval systems to generate an adversarial image to conceal the query image. The generated image looks nothing like the user intended query, but leads to identical or very similar retrieval results. Transferring attacks to fully unseen networks is challenging. We show successful attacks to partially unknown systems, by designing various loss functions for the adversarial image construction. These include loss functions, for example, for unknown global pooling operation or unknown input resolution by the retrieval system. We evaluate the attacks on standard retrieval benchmarks and compare the results retrieved with the original and adversarial image.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0c68638f-3be1-4fc2-9e93-dc8c9dd99a72Cited by top-tier papers11
- Multi-Expert Adversarial Attack Detection in Person Re-identification Using Context InconsistencyXueping Wang, Shasha Li, Min Liu, Yaonan Wang et al.ICCV 2021 · 34 citations
- Learning to Attack Real-World Models for Person Re-identification via Virtual-Guided Meta-LearningFengxiang Yang, Zhun Zhong, Hong Liu, Zheng Wang et al.AAAI 2021 · 23 citations
- Discriminator-free Generative Adversarial AttackShaohao Lu, Yuqiao Xian, Ke Yan, Yi Hu et al.ACM MM 2021 · 21 citations
- Practical Relative Order Attack in Deep RankingMo Zhou, Le Wang, Zhenxing Niu, Qilin Zhang et al.ICCV 2021 · 19 citations
- Enhancing Adversarial Robustness for Deep Metric LearningMo Zhou, Vishal M. PatelCVPR 2022 · 17 citations
Builds on3
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Hidden Voice CommandsNicholas Carlini, Pratyush Mishra, Tavish Vaidya, Yuankai Zhang et al.USENIX Security 2016 · 672 citations
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong et al.ICCV 2019 · 115 citations
Related papers
- QAIR: Practical Query-Efficient Black-Box Attacks for Image RetrievalXiaodan Li, Jinfeng Li, Yuefeng Chen, Shaokai Ye et al.CVPR 2021
- AdvHash: Set-to-set Targeted Attack on Deep Hashing with One Single Adversarial PatchShengshan Hu, Yechao Zhang, Xiaogeng Liu, Leo Yu Zhang et al.ACM MM 2021 · 34 citations
- DAIR: A Query-Efficient Decision-based Attack on Image Retrieval SystemsMingyang Chen, Junda Lu, Yi Wang, Jianbin Qin et al.SIGIR 2021 · 20 citations
- Once and for All: Universal Transferable Adversarial Perturbation against Deep Hashing-Based Facial Image RetrievalLong Tang, Dengpan Ye, Yunna Lv, Chuanxi Chen et al.AAAI 2024 · 13 citations
- You See What I Want You To See: Exploring Targeted Black-Box Transferability Attack for Hash-Based Image Retrieval SystemsYanru Xiao, Cong WangCVPR 2021
