Attacking Visual Language Grounding with Adversarial Examples: A Case Study on Neural Image Captioning

Attacking Visual Language Grounding with Adversarial Examples: A Case Study on Neural Image Captioning
复制标题

DOI:
10.18653/v1/p18-1241
复制
发表时间:
2017-12
期刊:
Adv. Eng. Informatics
影响因子:
--
通讯作者:
Hongge Chen;Huan Zhang;Pin-Yu Chen;Jinfeng Yi;Cho-Jui Hsieh
Hongge Chen;Huan Zhang;Pin-Yu Chen;Jinfeng Yi;Cho-Jui Hsieh
中科院分区:
其他
文献类型:
--
作者:
Hongge Chen;Huan Zhang;Pin-Yu Chen;Jinfeng Yi;Cho-Jui Hsieh

文献摘要

被引文献

相似文献

视觉语言基础在现代神经图像字幕系统中被广泛研究,其通常采用由两个主要组件组成的编码器-解码器框架:用于图像特征提取的卷积神经网络(CNN)和用于语言字幕生成的递归神经网络(RNN)。为了研究机器视觉和感知中语言基础对对抗性扰动的鲁棒性,我们提出了Show-and-Fool,这是一种用于在神经图像字幕中制作对抗性示例的新算法。该算法提供了两种评估方法,检查我们是否可以误导神经图像字幕系统输出一些随机选择的字幕或关键字。我们广泛的实验表明,我们的算法可以成功地制作具有随机目标字幕或关键字的视觉相似的对抗性示例,并且对抗性示例可以高度转移到其他图像字幕系统。因此,我们的方法导致新的鲁棒性的影响神经图像字幕和视觉语言接地的新见解。
Visual language grounding is widely studied in modern neural image captioning systems, which typically adopts an encoder-decoder framework consisting of two principal components: a convolutional neural network (CNN) for image feature extraction and a recurrent neural network (RNN) for language caption generation. To study the robustness of language grounding to adversarial perturbations in machine vision and perception, we propose Show-and-Fool, a novel algorithm for crafting adversarial examples in neural image captioning. The proposed algorithm provides two evaluation approaches, which check if we can mislead neural image captioning systems to output some randomly chosen captions or keywords. Our extensive experiments show that our algorithm can successfully craft visually-similar adversarial examples with randomly targeted captions or keywords, and the adversarial examples can be made highly transferable to other image captioning systems. Consequently, our approach leads to new robustness implications of neural image captioning and novel insights in visual language grounding.