Enhancing Cross-Task Black-Box Transferability of Adversarial Examples With Dispersion Reduction

Enhancing Cross-Task Black-Box Transferability of Adversarial Examples With Dispersion Reduction
复制标题

DOI:
10.1109/cvpr42600.2020.00102
复制
发表时间:
2019-11
期刊:
2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)
影响因子:
--
通讯作者:
Yantao Lu;Yunhan Jia;Jianyu Wang-;Bai Li;Weiheng Chai;L. Carin;Senem Velipasalar
Yantao Lu;Yunhan Jia;Jianyu Wang-;Bai Li;Weiheng Chai;L. Carin;Senem Velipasalar
中科院分区:
其他
文献类型:
--
作者:
Yantao Lu;Yunhan Jia;Jianyu Wang-;Bai Li;Weiheng Chai;L. Carin;Senem Velipasalar

文献摘要

被引文献

相似文献

众所周知,神经网络很容易受到精心制作的对抗性示例的攻击,而这些恶意样本通常会转移,也就是说,它们甚至会与其他模型保持对抗性。尽管在模型之间的可转移性方面已经投入了大量的努力,但令人惊讶的是,很少有人关注跨任务可转移性,这代表了现实世界的网络犯罪情况,在这种情况下,需要同时避开不同防御/检测机制的集合。我们研究了对抗示例在广泛的现实世界计算机视觉任务中的可转移性,包括图像分类、对象检测、语义分割、显式内容检测和文本检测。我们提出的攻击最小化了内部特征映射的“分散”,克服了现有攻击的局限性,这些攻击需要特定于任务的损失函数和/或探测目标模型。我们对开源检测和分割模型以及谷歌云视觉(GCV) api提供的四种不同的计算机视觉任务进行了评估。我们证明,我们的方法优于现有的攻击,只需要适度的扰动,就可以大幅度降低多个CV任务的性能。
Neural networks are known to be vulnerable to carefully crafted adversarial examples, and these malicious samples often transfer, i.e., they remain adversarial even against other models. Although significant effort has been devoted to the transferability across models, surprisingly little attention has been paid to cross-task transferability, which represents the real-world cybercriminal's situation, where an ensemble of different defense/detection mechanisms need to be evaded all at once. We investigate the transferability of adversarial examples across a wide range of real-world computer vision tasks, including image classification, object detection, semantic segmentation, explicit content detection, and text detection. Our proposed attack minimizes the “dispersion” of the internal feature map, overcoming the limitations of existing attacks, that require task-specific loss functions and/or probing a target model. We conduct evaluation on open-source detection and segmentation models, as well as four different computer vision tasks provided by Google Cloud Vision (GCV) APIs. We demonstrate that our approach outperforms existing attacks by degrading performance of multiple CV tasks by a large margin with only modest perturbations.