Learning Optimization-based Adversarial Perturbations for Attacking Sequential Recognition Models
Xing Xu, Jiefu Chen, Jinhui Xiao, Zheng Wang, Yang Yang, Heng Tao Shen
摘要
A large number of recent studies on adversarial attack have verified that a Deep Neural Network (DNN) model designed for non-sequential recognition (NSR) tasks (e.g., classification, detection and segmentation) can be easily fooled by adversarial examples. However, only a few researches pay attention to the adversarial attack on sequential recognition (SR). They either apply the attack methods proposed for NSR to SR by neglecting the sequential dependencies, or focus on attacking specific SR models without considering the generality. In this paper, we study the adversarial attack on the general and popular DNN structure of CNN+RNN, i.e., the combination of convolutional neural network (CNN) and recurrent neural network (RNN), which has been widely used in various SR tasks. We take the scene text recognition (STR) and image captioning (IC) as case study, and derive the objective function for attacking the CNN+RNN based models with targeted and untargeted attack modes, and then developed an optimization-based algorithm to learn adversarial perturbations from the derived gradients of each character (or word) in sequence by incorporating the sequential dependencies. Extensive experiments show that our proposed method can effective fool several state-of-the-arts including four STR models and two IC models with higher successful rate and less time consumption, comparing to three latest attack methods.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper5
- Physical Backdoor Attacks to Lane Detection Systems in Autonomous DrivingXingshuo Han, Guowen Xu, Yuan Zhou, Xuehuan Yang 等ACM MM 2022 · 被引用 48 次
- Text's Armor: Optimized Local Adversarial Perturbation Against Scene Text Editing AttacksTao Xiang, Hangcheng Liu, Shangwei Guo, Hantao Liu 等ACM MM 2022 · 被引用 5 次
- My Brother Helps Me: Node Injection Based Adversarial Attack on Social Bot DetectionLanjun Wang, Xinran Qiao, Yanwei Xie, Weizhi Nie 等ACM MM 2023 · 被引用 3 次
- CAPatch: Physical Adversarial Patch against Image Captioning SystemsShibo Zhang, Yushi Cheng, Wenjun Zhu, Xiaoyu Ji 等USENIX Security 2023
- What if We Only Use Real Datasets for Scene Text Recognition? Toward Scene Text Recognition With Fewer LabelsJeonghun Baek, Yusuke Matsui, Kiyoharu AizawaCVPR 2021
相关 Paper
- What Machines See Is Not What They Get: Fooling Scene Text Recognition Models With Adversarial Text ImagesXing Xu, Jiefu Chen, Jinhui Xiao, Lianli Gao 等CVPR 2020
- Towards Irreversible Attack: Fooling Scene Text Recognition via Multi-Population Coevolution SearchJingyu Li, Pengwen Dai, Mingqing Zhu, Chengwei Wang 等NeurIPS 2025
- Seq2Sick: Evaluating the Robustness of Sequence-to-Sequence Models with Adversarial ExamplesMinhao Cheng, Jinfeng Yi, Pin-Yu Chen, Huan Zhang 等AAAI 2020 · 被引用 268 次
- Adversarial Attack and Defense of Structured Prediction ModelsWenjuan Han, Liwen Zhang, Yong Jiang, Kewei TuEMNLP 2020 · 被引用 32 次
- Context-Aware Selective Label Smoothing for Calibrating Sequence Recognition ModelShuangping Huang, Yu Luo, Zhenzhou Zhuang, Jin-Gang Yu 等ACM MM 2021 · 被引用 10 次
