360-Attack: Distortion-Aware Perturbations from Perspective-Views
Yunjian Zhang, Yanwei Liu, Jinxia Liu, Jingbo Miao, Antonios Argyriou, Liming Wang, Zhen Xu
Abstract
The application of deep neural networks (DNNs) on 360-degree images has achieved remarkable progress in the recent years. However, DNNs have been demonstrated to be vulnerable to well-crafted adversarial examples, which may trigger severe safety problems in the real-world applications based on 360-degree images. In this paper, we propose an adversarial attack targeting spherical images, called 360-attactk, that transfers adversarial perturbations from perspective-view (PV) images to a final adversarial spherical image. Given a target spherical image, we first represent it with a set of planar PV images, and then perform 2D attacks on them to obtain adversarial PV images. Considering the issue of the projective distortion between spherical and PV images, we propose a distortion-aware attack to reduce the negative impact of distortion on attack. Moreover, to reconstruct the final adversarial spherical image with high aggressiveness, we calculate the spherical saliency map with a novel spherical spectrum method and next propose a saliency-aware fusion strategy that merges multiple inverse perspective projections for the same position on the spherical image. Extensive experimental results show that 360-attack is effective for disturbing spherical images in the black-box setting. Our attack also proves the presence of adversarial transferability from Z2 to SO(3) groups.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 60b07383-7cb0-46e8-8762-6b9efc3df293Builds on9
- Nesterov Accelerated Gradient and Scale Invariance for Adversarial AttacksJiadong Lin, Chuanbiao Song, Kun He, Liwei Wang et al.ICLR 2020 · 765 citations
- Minimally distorted Adversarial Examples with a Fast Adaptive Boundary AttackFrancesco Croce, Matthias HeinICML 2020 · 597 citations
- Feature Importance-aware Transferable Adversarial AttacksZhibo Wang, Hengchang Guo, Zhifei Zhang, Wenxin Liu et al.ICCV 2021 · 306 citations
- Enhancing Adversarial Example Transferability With an Intermediate Level AttackQian Huang, Isay Katsman, Zeqi Gu, Horace He et al.ICCV 2019 · 293 citations
- Stereopagnosia: Fooling Stereo Networks with Adversarial PerturbationsAlex Wong, Mukund Mundhra, Stefano SoattoAAAI 2021 · 33 citations
Related papers
- Leveraging Spatial Invariance to Boost Adversarial TransferabilityZihan Zhou, Li Li, Yanli Ren, Chuan Qin et al.ICCV 2025 · 1 citation
- SalGCN: Saliency Prediction for 360-Degree Images Based on Spherical Graph Convolutional NetworksHaoran Lv, Qin Yang, Chenglin Li, Wenrui Dai et al.ACM MM 2020 · 24 citations
- Multi-view Correlation based Black-box Adversarial Attack for 3D Object DetectionBingyu Liu, Yuhong Guo, Jianan Jiang, Jian Tang et al.KDD 2021 · 10 citations
- Universal 3-Dimensional Perturbations for Black-Box Attacks on Video Recognition SystemsShangyu Xie, Han Wang, Yu Kong, Yuan HongS&P 2022 · 32 citations
- Towards Viewpoint-Invariant Visual Recognition via Adversarial TrainingShouwei Ruan, Yinpeng Dong, Hang Su, Jianteng Peng et al.ICCV 2023 · 23 citations
