Effective and Efficient Vote Attack on Capsule Networks
Jindong Gu, Baoyuan Wu, Volker Tresp
Abstract
Standard Convolutional Neural Networks (CNNs) can be easily fooled by images with small quasi-imperceptible artificial perturbations. As alternatives to CNNs, the recently proposed Capsule Networks (CapsNets) are shown to be more robust to white-box attacks than CNNs under popular attack protocols. Besides, the class-conditional reconstruction part of CapsNets is also used to detect adversarial examples. In this work, we investigate the adversarial robustness of CapsNets, especially how the inner workings of CapsNets change when the output capsules are attacked. The first observation is that adversarial examples misled CapsNets by manipulating the votes from primary capsules. Another observation is the high computational cost, when we directly apply multi-step attack methods designed for CNNs to attack CapsNets, due to the computationally expensive routing mechanism. Motivated by these two observations, we propose a novel vote attack where we attack votes of CapsNets directly. Our vote attack is not only effective but also efficient by circumventing the routing process. Furthermore, we integrate our vote attack into the detection-aware attack paradigm, which can successfully bypass the class-conditional reconstruction based detection method. Extensive experiments demonstrate the superior attack performance of our vote attack on CapsNets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a9877bfe-e3ec-457e-a4ed-421110e76a55Cited by top-tier papers6
- LAS-AT: Adversarial Training with Learnable Attack StrategyXiaojun Jia, Yong Zhang, Baoyuan Wu, Ke Ma et al.CVPR 2022 · 140 citations
- Interpretable Graph Capsule Networks for Object RecognitionJindong GuAAAI 2021 · 42 citations
- Why Capsule Neural Networks Do Not Scale: Challenging the Dynamic Parse-Tree AssumptionMatthias Mitterreiter, Marcel Koch, Joachim Giesen, Sören LaueAAAI 2023 · 17 citations
- Multimodal Unlearnable Examples: Protecting Data against Multimodal Contrastive LearningXinwei Liu, Xiaojun Jia, Yuan Xun, Siyuan Liang et al.ACM MM 2024 · 11 citations
- Influencer Backdoor Attack on Semantic SegmentationHaoheng Lan, Jindong Gu, Philip Torr, Hengshuang ZhaoICLR 2024 · 10 citations
Builds on11
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
- Capsule Routing via Variational BayesFabio De Sousa Ribeiro, Georgios Leontidis, Stefanos D. KolliasAAAI 2020 · 93 citations
- Capsules with Inverted Dot-Product Attention RoutingYao-Hung Hubert Tsai, Nitish Srivastava, Hanlin Goh, Ruslan SalakhutdinovICLR 2020 · 91 citations
Related papers
- Detecting and Diagnosing Adversarial Images with Class-Conditional Capsule ReconstructionsYao Qin, Nicholas Frosst, Sara Sabour, Colin Raffel et al.ICLR 2020 · 76 citations
- Capsule Network Is Not More Robust Than Convolutional NetworkJindong Gu, Volker Tresp, Han HuCVPR 2021
- PT-CapsNet: A Novel Prediction-Tuning Capsule Network Suitable for Deeper ArchitecturesChenbin Pan, Senem VelipasalarICCV 2021 · 11 citations
- Improving the Robustness of Capsule Networks to Image Affine TransformationsJindong Gu, Volker TrespCVPR 2020
- Enabling Equivariance for Arbitrary Lie GroupsLachlan E. MacDonald, Sameera Ramasinghe, Simon LuceyCVPR 2022 · 11 citations
