Towards Large Yet Imperceptible Adversarial Image Perturbations With Perceptual Color Distance
Zhengyu Zhao, Zhuoran Liu, Martha A. Larson
摘要
The success of image perturbations that are designed to fool image classifier is assessed in terms of both adversarial effect and visual imperceptibility. The conventional assumption on imperceptibility is that perturbations should strive for tight L p -norm bounds in RGB space. In this work, we drop this assumption by pursuing an approach that exploits human color perception, and more specifically, minimizing perturbation size with respect to perceptual color distance. Our first approach, Perceptual Color distance C&W (PerC-C&W), extends the widely-used C&W approach and produces larger RGB perturbations. PerC-C&W is able to maintain adversarial strength, while contributing to imperceptibility. Our second approach, Perceptual Color distance Alternating Loss (PerC-AL), achieves the same outcome, but does so more efficiently by alternating between the classification loss and perceptual color difference when updating perturbations. Experimental evaluation shows PerC approaches outperform conventional L p approaches in terms of robustness and transferability, and also demonstrates that the PerC distance can provide added value on top of existing structure-based methods to creating image perturbations.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper38
- Content-based Unrestricted Adversarial AttackZhaoyu Chen, Bo Li, Shuang Wu, Kaixun Jiang 等NeurIPS 2023 · 被引用 132 次
- Frequency-driven Imperceptible Adversarial Attack on Semantic SimilarityCheng Luo, Qinliang Lin, Weicheng Xie, Bizhu Wu 等CVPR 2022 · 被引用 132 次
- AdvDrop: Adversarial Attack to DNNs by Dropping InformationRanjie Duan, Yuefeng Chen, Dantong Niu, Yun Yang 等ICCV 2021 · 被引用 127 次
- Hard to Forget: Poisoning Attacks on Certified Machine UnlearningNeil G. Marchant, Benjamin I. P. Rubinstein, Scott AlfeldAAAI 2022 · 被引用 95 次
- AdvDiffuser: Natural Adversarial Example Synthesis with Diffusion ModelsXinquan Chen, Xitong Gao, Juanjuan Zhao, Kejiang Ye 等ICCV 2023 · 被引用 94 次
它引用的顶会 Paper6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 被引用 1,633 次
- Sparse and Imperceivable Adversarial AttacksFrancesco Croce, Matthias HeinICCV 2019 · 被引用 228 次
- Unrestricted Adversarial Examples via Semantic ManipulationAnand Bhattad, Min Jin Chong, Kaizhao Liang, Bo Li 等ICLR 2020 · 被引用 177 次
- What Else Can Fool Deep Learning? Addressing Color Constancy Errors on Deep Neural Network PerformanceMahmoud Afifi, Michael S. BrownICCV 2019 · 被引用 123 次
相关 Paper
- ColorFool: Semantic Adversarial ColorizationAli Shahin Shamsabadi, Ricardo Sánchez-Matilla, Andrea CavallaroCVPR 2020
- Natural Color Fool: Towards Boosting Black-box Unrestricted AttacksShengming Yuan, Qilong Zhang, Lianli Gao, Yaya Cheng 等NeurIPS 2022 · 被引用 86 次
- Perceptual Adversarial Robustness: Defense Against Unseen Threat ModelsCassidy Laidlaw, Sahil Singla, Soheil FeiziICLR 2021 · 被引用 217 次
- Explaining Classifiers Using Adversarial Perturbations on the Perceptual BallAndrew Elliott, Stephen Law, Chris RussellCVPR 2021
- Perceptual Attacks of No-Reference Image Quality Models with Human-in-the-LoopWeixia Zhang, Dingquan Li, Xiongkuo Min, Guangtao Zhai 等NeurIPS 2022 · 被引用 55 次
