Effective and Efficient Vote Attack on Capsule Networks
Jindong Gu, Baoyuan Wu, Volker Tresp
摘要
Standard Convolutional Neural Networks (CNNs) can be easily fooled by images with small quasi-imperceptible artificial perturbations. As alternatives to CNNs, the recently proposed Capsule Networks (CapsNets) are shown to be more robust to white-box attacks than CNNs under popular attack protocols. Besides, the class-conditional reconstruction part of CapsNets is also used to detect adversarial examples. In this work, we investigate the adversarial robustness of CapsNets, especially how the inner workings of CapsNets change when the output capsules are attacked. The first observation is that adversarial examples misled CapsNets by manipulating the votes from primary capsules. Another observation is the high computational cost, when we directly apply multi-step attack methods designed for CNNs to attack CapsNets, due to the computationally expensive routing mechanism. Motivated by these two observations, we propose a novel vote attack where we attack votes of CapsNets directly. Our vote attack is not only effective but also efficient by circumventing the routing process. Furthermore, we integrate our vote attack into the detection-aware attack paradigm, which can successfully bypass the class-conditional reconstruction based detection method. Extensive experiments demonstrate the superior attack performance of our vote attack on CapsNets.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- LAS-AT: Adversarial Training with Learnable Attack StrategyXiaojun Jia, Yong Zhang, Baoyuan Wu, Ke Ma 等CVPR 2022 · 被引用 140 次
- Interpretable Graph Capsule Networks for Object RecognitionJindong GuAAAI 2021 · 被引用 42 次
- Why Capsule Neural Networks Do Not Scale: Challenging the Dynamic Parse-Tree AssumptionMatthias Mitterreiter, Marcel Koch, Joachim Giesen, Sören LaueAAAI 2023 · 被引用 17 次
- Multimodal Unlearnable Examples: Protecting Data against Multimodal Contrastive LearningXinwei Liu, Xiaojun Jia, Yuan Xun, Siyuan Liang 等ACM MM 2024 · 被引用 11 次
- Influencer Backdoor Attack on Semantic SegmentationHaoheng Lan, Jindong Gu, Philip Torr, Hengshuang ZhaoICLR 2024 · 被引用 10 次
它引用的顶会 Paper11
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 被引用 1,765 次
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 被引用 1,633 次
- Capsule Routing via Variational BayesFabio De Sousa Ribeiro, Georgios Leontidis, Stefanos D. KolliasAAAI 2020 · 被引用 93 次
- Capsules with Inverted Dot-Product Attention RoutingYao-Hung Hubert Tsai, Nitish Srivastava, Hanlin Goh, Ruslan SalakhutdinovICLR 2020 · 被引用 91 次
相关 Paper
- Detecting and Diagnosing Adversarial Images with Class-Conditional Capsule ReconstructionsYao Qin, Nicholas Frosst, Sara Sabour, Colin Raffel 等ICLR 2020 · 被引用 76 次
- Capsule Network Is Not More Robust Than Convolutional NetworkJindong Gu, Volker Tresp, Han HuCVPR 2021
- PT-CapsNet: A Novel Prediction-Tuning Capsule Network Suitable for Deeper ArchitecturesChenbin Pan, Senem VelipasalarICCV 2021 · 被引用 11 次
- Improving the Robustness of Capsule Networks to Image Affine TransformationsJindong Gu, Volker TrespCVPR 2020
- Enabling Equivariance for Arbitrary Lie GroupsLachlan E. MacDonald, Sameera Ramasinghe, Simon LuceyCVPR 2022 · 被引用 11 次
