Catastrophic Child's Play: Easy to Perform, Hard to Defend Adversarial Attacks

Catastrophic Child's Play: Easy to Perform, Hard to Defend Adversarial Attacks
复制标题

DOI:
10.1109/cvpr.2019.00945
复制
发表时间:
2019-06
期刊:
2019 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)
影响因子:
--
通讯作者:
Chih-Hui Ho;Brandon Leung;Erik Sandström;Yen Chang;N. Vasconcelos
Chih-Hui Ho;Brandon Leung;Erik Sandström;Yen Chang;N. Vasconcelos
中科院分区:
其他
文献类型:
--
作者:
Chih-Hui Ho;Brandon Leung;Erik Sandström;Yen Chang;N. Vasconcelos

文献摘要

相似文献

考虑了对抗性 CNN 攻击的问题,重点是那些执行起来很简单但难以防御的攻击。提出了使用现实世界对象操作来研究此类攻击的框架。与过去的大多数工作不同,该框架支持基于小图像扰动和大图像扰动的攻击设计,通过相机抖动和姿势变化来实现。提出了一种用于收集此类扰动并确定其可感知性的设置。有人认为,可感知性取决于上下文,并且在不可感知的扰动和语义上不可感知的扰动之间进行了区分。虽然前者在图像比较中幸存下来,但后者是可感知的,但对人类物体识别没有影响。提出了一种使用 Turk 实验确定扰动的可感知性的程序,并组装了两个扰动类别的数据集,该数据集能够对对象操纵攻击进行可复制的研究。使用基于许多数据集、CNN 模型和文献算法的防御进行的实验阐明了防御这些攻击的难度 - 事实上,现有的防御措施均未发现对这些攻击有效。通过现实世界的数据增强可以获得更好的结果,但即使这样也不是万无一失的。这些结果证实了这样的假设:当前的 CNN 很容易受到即使是儿童也可以实施的攻击,并且这种攻击可能难以防御。
The problem of adversarial CNN attacks is considered, with an emphasis on attacks that are trivial to perform but difficult to defend. A framework for the study of such attacks is proposed, using real world object manipulations. Unlike most works in the past, this framework supports the design of attacks based on both small and large image perturbations, implemented by camera shake and pose variation. A setup is proposed for the collection of such perturbations and determination of their perceptibility. It is argued that perceptibility depends on context, and a distinction is made between imperceptible and semantically imperceptible perturbations. While the former survives image comparisons, the latter are perceptible but have no impact on human object recognition. A procedure is proposed to determine the perceptibility of perturbations using Turk experiments, and a dataset of both perturbation classes which enables replicable studies of object manipulation attacks, is assembled. Experiments using defenses based on many datasets, CNN models, and algorithms from the literature elucidate the difficulty of defending these attacks -- in fact, none of the existing defenses is found effective against them. Better results are achieved with real world data augmentation, but even this is not foolproof. These results confirm the hypothesis that current CNNs are vulnerable to attacks implementable even by a child, and that such attacks may prove difficult to defend.