Semantic Adversarial Attacks: Parametric Transformations That Fool Deep Classifiers
Ameya Joshi, Amitangshu Mukherjee, Soumik Sarkar, Chinmay Hegde
摘要
Deep neural networks have been shown to exhibit an intriguing vulnerability to adversarial input images corrupted with imperceptible perturbations. However, the majority of adversarial attacks assume global, fine-grained control over the image pixel space. In this paper, we consider a different setting: what happens if the adversary could only alter specific attributes of the input image? These would generate inputs that might be perceptibly different, but still natural-looking and enough to fool a classifier. We propose a novel approach to generate such ``semantic'' adversarial examples by optimizing a particular adversarial loss over the range-space of a parametric conditional generative model. We demonstrate implementations of our attacks on binary classifiers trained on face images, and show that such natural-looking semantic adversarial examples exist. We evaluate the effectiveness of our attack on synthetic and real data, and present detailed comparisons with existing attack methods. We supplement our empirical results with theoretical bounds that demonstrate the existence of such parametric adversarial examples.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper20
- Unrestricted Adversarial Examples via Semantic ManipulationAnand Bhattad, Min Jin Chong, Kaizhao Liang, Bo Li 等ICLR 2020 · 被引用 177 次
- Attribute-Guided Adversarial Training for Robustness to Natural PerturbationsTejas Gokhale, Rushil Anirudh, Bhavya Kailkhura, Jayaraman J. Thiagarajan 等AAAI 2021 · 被引用 42 次
- Adversarial Item Promotion: Vulnerabilities at the Core of Top-N Recommenders that Use Images to Address Cold StartZhuoran Liu, Martha A. LarsonWWW 2021 · 被引用 34 次
- Robust Feature-Level Adversaries are Interpretability ToolsStephen Casper, Max Nadeau, Dylan Hadfield-Menell, Gabriel KreimanNeurIPS 2022 · 被引用 34 次
- Exposing previously undetectable faults in deep neural networksIsaac Dunn, Hadrien Pouget, Daniel Kroening, Tom MelhamISSTA 2021 · 被引用 25 次
它引用的顶会 Paper1
相关 Paper
- Constructing Semantics-Aware Adversarial Examples with a Probabilistic PerspectiveAndi Zhang, Mingtian Zhang, Damon WischikNeurIPS 2024 · 被引用 6 次
- Adv-Attribute: Inconspicuous and Transferable Adversarial Attack on Face RecognitionShuai Jia, Bangjie Yin, Taiping Yao, Shouhong Ding 等NeurIPS 2022 · 被引用 84 次
- Evading Forensic Classifiers with Attribute-Conditioned Adversarial FacesFahad Shamshad, Koushik Srivatsan, Karthik NandakumarCVPR 2023
- Natural Language Induced Adversarial ImagesXiaopei Zhu, Peiyang Xu, Guanning Zeng, Yinpeng Dong 等ACM MM 2024 · 被引用 1 次
- Frequency-driven Imperceptible Adversarial Attack on Semantic SimilarityCheng Luo, Qinliang Lin, Weicheng Xie, Bizhu Wu 等CVPR 2022 · 被引用 132 次
