Semantic-Aware Multi-Label Adversarial Attacks
Hassan Mahmood, Ehsan Elhamifar
Abstract
Despite its importance, generating attacks for multilabel learning (MLL) models has received much less attention compared to multi-class recognition. Attacking an MLL model by optimizing a loss on the target set of labels has often the undesired consequence of changing the predictions for other labels. On the other hand, adding a loss on the remaining labels to keep them fixed leads to highly negatively correlated gradient directions, reducing the attack effectiveness. In this paper, we develop a framework for crafting effective and semantic-aware adversarial attacks for MLL. First, to obtain an attack that leads to semantically consistent predictions across all labels, we find a minimal superset of the target labels, referred to as consistent target set. To do so, we develop an efficient search algorithm over a knowledge graph, which encodes label dependencies. Next, we propose an optimization that searches for an attack that modifies the predictions of labels in the consistent target set while ensuring other labels will not get affected. This leads to an efficient algorithm that projects the gradient of the consistent target set loss onto the orthogonal direction of the gradient of the loss on other labels. Our framework can generate attacks on different target set sizes and for MLL with thousands of labels (as in OpenImages). Finally, by extensive experiments on three datasets and several MLL models, we show that our method generates both successful and semantically consistent attacks.<sup xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">1</sup><sup xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">1</sup>The code of this work is available at https://github.com/hassan-mahmood/SemanticMLLAttacks.git
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dfe903dc-35be-4f74-bf9c-18b3872c552aCited by top-tier papers3
- PatchDEMUX: A Certifiably Robust Framework for Multi-label Classifiers Against Adversarial PatchesDennis Jacob, Chong Xiang, Prateek MittalCVPR 2025
- Compositional Targeted Multi-Label Universal PerturbationsHassan Mahmood, Ehsan ElhamifarCVPR 2025
- GSBAK: top-K Geometric Score-based Black-box AttackMd Farhamdur Reza, Richeng Jin, Tianfu Wu, Huaiyu DaiICLR 2025
Builds on30
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
- Asymmetric Loss For Multi-Label ClassificationTal Ridnik, Emanuel Ben Baruch, Nadav Zamir, Asaf Noy et al.ICCV 2021 · 778 citations
- Learning Semantic-Specific Graph Representation for Multi-Label Image RecognitionTianshui Chen, Muxin Xu, Xiaolu Hui, Hefeng Wu et al.ICCV 2019 · 347 citations
Related papers
- TkML-AP: Adversarial Attacks to Top-k Multi-Label LearningShu Hu, Lipeng Ke, Xin Wang, Siwei LyuICCV 2021 · 38 citations
- DART: Distribution-Aware Adaptive Relational Transfer for Adversarial Attacks against Closed-Source MLLMsKaidi Hu, Guancheng Wan, Xiao Luo, Ruigang YangICML 2026
- Provably Consistent Partial-Label LearningLei Feng, Jiaqi Lv, Bo Han, Miao Xu et al.NeurIPS 2020 · 188 citations
- MOS-Attack: A Scalable Multi-objective Adversarial Attack FrameworkPing Guo, Cheng Gong, Xi Lin, Fei Liu et al.CVPR 2025
- When Measures are Unreliable: Imperceptible Adversarial Perturbations toward Top-k Multi-Label LearningYuchen Sun, Qianqian Xu, Zitai Wang, Qingming HuangACM MM 2023 · 2 citations
