Zero-Query Transfer Attacks on Context-Aware Object Detectors
Zikui Cai, Shantanu Rane, Alejandro E. Brito, Chengyu Song, Srikanth V. Krishnamurthy, Amit K. Roy-Chowdhury, M. Salman Asif
摘要
Adversarial attacks perturb images such that a deep neural network produces incorrect classification results. A promising approach to defend against adversarial attacks on natural multi-object scenes is to impose a context-consistency check, wherein, if the detected objects are not consistent with an appropriately defined context, then an attack is suspected. Stronger attacks are needed to fool such context-aware detectors. We present the first approach for generating context-consistent adversarial attacks that can evade the context-consistency check of black-box object detectors operating on complex, natural scenes. Unlike many black-box attacks that perform repeated attempts and open themselves to detection, we assume a “zero-query” setting, where the attacker has no knowledge of the classification decisions of the victim system. First, we derive multiple attack plans that assign incorrect labels to victim objects in a context-consistent manner. Then we design and use a novel data structure that we call the perturbation success probability matrix, which enables us to filter the attack plans and choose the one most likely to succeed. This final attack plan is implemented using a perturbation-bounded adversarial attack algorithm. We compare our zero-query attack against a few-query scheme that repeatedly checks if the victim system is fooled. We also compare against state-of-the-art context-agnostic attacks. Against a context-aware defense, the fooling rate of our zero-query approach is significantly higher than context-agnostic approaches and higher than that achievable with up to three rounds of the fewquery scheme.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- GAMA: Generative Adversarial Multi-Object Scene AttacksAbhishek Aich, Calvin-Khang Ta, Akash Gupta, Chengyu Song 等NeurIPS 2022 · 被引用 26 次
- Semantic-Aware Multi-Label Adversarial AttacksHassan Mahmood, Ehsan ElhamifarCVPR 2024 · 被引用 3 次
- Ensemble-based Blackbox Attacks on Dense PredictionZikui Cai, Yaoteng Tan, M. Salman AsifCVPR 2023
- GLOW: Global Layout Aware Attacks on Object DetectionJun Bao, Buyu Liu, Kui Ren, Jun YuCVPR 2024
- BotScreen: Trust Everybody, but Cut the Aimbots YourselfMinyeop Choi, Gihyuk Ko, Sang Kil ChaUSENIX Security 2023
它引用的顶会 Paper11
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 被引用 1,633 次
- MagNet: A Two-Pronged Defense against Adversarial ExamplesDongyu Meng, Hao ChenCCS 2017 · 被引用 1,295 次
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 被引用 797 次
- Practical No-box Adversarial Attacks against DNNsQizhang Li, Yiwen Guo, Hao ChenNeurIPS 2020 · 被引用 73 次
相关 Paper
- Exploiting Multi-Object Relationships for Detecting Adversarial Attacks in Complex ScenesMingjun Yin, Shasha Li, Zikui Cai, Chengyu Song 等ICCV 2021 · 被引用 25 次
- A Geometry-Inspired Decision-Based AttackYujia Liu, Seyed-Mohsen Moosavi-Dezfooli, Pascal FrossardICCV 2019 · 被引用 55 次
- ColorFool: Semantic Adversarial ColorizationAli Shahin Shamsabadi, Ricardo Sánchez-Matilla, Andrea CavallaroCVPR 2020
- Context-Aware Transfer Attacks for Object DetectionZikui Cai, Xinxin Xie, Shasha Li, Mingjun Yin 等AAAI 2022 · 被引用 41 次
- GeoDA: A Geometric Framework for Black-Box Adversarial AttacksAli Rahmati, Seyed-Mohsen Moosavi-Dezfooli, Pascal Frossard, Huaiyu DaiCVPR 2020
