Learning Optimization-based Adversarial Perturbations for Attacking Sequential Recognition Models
Xing Xu, Jiefu Chen, Jinhui Xiao, Zheng Wang, Yang Yang, Heng Tao Shen
Abstract
A large number of recent studies on adversarial attack have verified that a Deep Neural Network (DNN) model designed for non-sequential recognition (NSR) tasks (e.g., classification, detection and segmentation) can be easily fooled by adversarial examples. However, only a few researches pay attention to the adversarial attack on sequential recognition (SR). They either apply the attack methods proposed for NSR to SR by neglecting the sequential dependencies, or focus on attacking specific SR models without considering the generality. In this paper, we study the adversarial attack on the general and popular DNN structure of CNN+RNN, i.e., the combination of convolutional neural network (CNN) and recurrent neural network (RNN), which has been widely used in various SR tasks. We take the scene text recognition (STR) and image captioning (IC) as case study, and derive the objective function for attacking the CNN+RNN based models with targeted and untargeted attack modes, and then developed an optimization-based algorithm to learn adversarial perturbations from the derived gradients of each character (or word) in sequence by incorporating the sequential dependencies. Extensive experiments show that our proposed method can effective fool several state-of-the-arts including four STR models and two IC models with higher successful rate and less time consumption, comparing to three latest attack methods.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get bf54832e-b6e3-408e-a220-7415ff019487Cited by top-tier papers5
- Physical Backdoor Attacks to Lane Detection Systems in Autonomous DrivingXingshuo Han, Guowen Xu, Yuan Zhou, Xuehuan Yang et al.ACM MM 2022 · 48 citations
- Text's Armor: Optimized Local Adversarial Perturbation Against Scene Text Editing AttacksTao Xiang, Hangcheng Liu, Shangwei Guo, Hantao Liu et al.ACM MM 2022 · 5 citations
- My Brother Helps Me: Node Injection Based Adversarial Attack on Social Bot DetectionLanjun Wang, Xinran Qiao, Yanwei Xie, Weizhi Nie et al.ACM MM 2023 · 3 citations
- CAPatch: Physical Adversarial Patch against Image Captioning SystemsShibo Zhang, Yushi Cheng, Wenjun Zhu, Xiaoyu Ji et al.USENIX Security 2023
- What if We Only Use Real Datasets for Scene Text Recognition? Toward Scene Text Recognition With Fewer LabelsJeonghun Baek, Yusuke Matsui, Kiyoharu AizawaCVPR 2021
Related papers
- What Machines See Is Not What They Get: Fooling Scene Text Recognition Models With Adversarial Text ImagesXing Xu, Jiefu Chen, Jinhui Xiao, Lianli Gao et al.CVPR 2020
- Towards Irreversible Attack: Fooling Scene Text Recognition via Multi-Population Coevolution SearchJingyu Li, Pengwen Dai, Mingqing Zhu, Chengwei Wang et al.NeurIPS 2025
- Seq2Sick: Evaluating the Robustness of Sequence-to-Sequence Models with Adversarial ExamplesMinhao Cheng, Jinfeng Yi, Pin-Yu Chen, Huan Zhang et al.AAAI 2020 · 268 citations
- Adversarial Attack and Defense of Structured Prediction ModelsWenjuan Han, Liwen Zhang, Yong Jiang, Kewei TuEMNLP 2020 · 32 citations
- Context-Aware Selective Label Smoothing for Calibrating Sequence Recognition ModelShuangping Huang, Yu Luo, Zhenzhou Zhuang, Jin-Gang Yu et al.ACM MM 2021 · 10 citations
