Morié Attack (MA): A New Potential Risk of Screen Photos
Dantong Niu, Ruohao Guo, Yisen Wang
摘要
Images, captured by a camera, play a critical role in training Deep Neural Networks (DNNs). Usually, we assume the images acquired by cameras are consistent with the ones perceived by human eyes. However, due to the different physical mechanisms between human-vision and computer-vision systems, the final perceived images could be very different in some cases, for example shooting on digital monitors. In this paper, we find a special phenomenon in digital image processing, the moiré effect, that could cause unnoticed security threats to DNNs. Based on it, we propose a Moiré Attack (MA) that generates the physical-world moiré pattern adding to the images by mimicking the shooting process of digital devices. Extensive experiments demonstrate that our proposed digital Moiré Attack (MA) is a perfect camouflage for attackers to tamper with DNNs with a high success rate (100.0% for untargeted and 97.0% for targeted attack with the noise budget = 4), high transferability rate across different models, and high robustness under various defenses. Furthermore, MA owns great stealthiness because the moiré effect is unavoidable due to the camera's inner physical structure, which therefore hardly attracts the awareness of humans. Our code is available at https://github.com/Dantong88/Moire_Attack .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Adversarial Examples Are Not Real FeaturesAng Li, Yifei Wang, Yiwen Guo, Yisen WangNeurIPS 2023 · 被引用 24 次
- Learning Image Demoiréing from Unpaired Real DataYunshan Zhong, Yuyao Zhou, Yuxin Zhang, Fei Chao 等AAAI 2024 · 被引用 9 次
- UniDemoiré: Towards Universal Image Demoiréing with Data Generation and SynthesisZemin Yang, Yujing Sun, Xidong Peng, Siu Ming Yiu 等AAAI 2025 · 被引用 3 次
它引用的顶会 Paper7
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 被引用 1,633 次
- Skip Connections Matter: On the Transferability of Adversarial Examples Generated with ResNetsDongxian Wu, Yisen Wang, Shu-Tao Xia, James Bailey 等ICLR 2020 · 被引用 357 次
- A Unified Approach to Interpreting and Boosting Adversarial TransferabilityXin Wang, Jie Ren, Shuyun Lin, Xiangming Zhu 等ICLR 2021 · 被引用 113 次
- Adversarial Camouflage: Hiding Physical-World Attacks With Natural StylesRanjie Duan, Xingjun Ma, Yisen Wang, James Bailey 等CVPR 2020
相关 Paper
- Moiré Backdoor Attack (MBA): A Novel Trigger for Pedestrian Detectors in the Physical WorldHui Wei, Hanxun Yu, Kewei Zhang, Zhixiang Wang 等ACM MM 2023 · 被引用 7 次
- Mop Moiré Patterns Using MopNetBin He, Ce Wang, Boxin Shi, Lingyu DuanICCV 2019 · 被引用 101 次
- Effectively Learning Moiré QR Code Decryption from Simulated DataYu Lu, Hao Pan, Feitong Tan, Yi-Chao Chen 等INFOCOM 2023 · 被引用 3 次
- Revisiting Adversarial Patches for Designing Camera-Agnostic Attacks against Person DetectionHui Wei, Zhixiang Wang, Kewei Zhang, Jiaqi Hou 等NeurIPS 2024 · 被引用 22 次
- PatchBackdoor: Backdoor Attack against Deep Neural Networks without Model ModificationYizhen Yuan, Rui Kong, Shenghao Xie, Yuanchun Li 等ACM MM 2023 · 被引用 12 次
