NICGSlowDown: Evaluating the Efficiency Robustness of Neural Image Caption Generation Models

NICGSlowDown: Evaluating the Efficiency Robustness of Neural Image Caption Generation Models
复制标题

DOI:
10.1109/cvpr52688.2022.01493
复制
发表时间:
2022-03
期刊:
2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)
影响因子:
--
通讯作者:
Simin Chen;Zihe Song;Mirazul Haque;Cong Liu;Wei Yang
Simin Chen;Zihe Song;Mirazul Haque;Cong Liu;Wei Yang
中科院分区:
其他
文献类型:
--
作者:
Simin Chen;Zihe Song;Mirazul Haque;Cong Liu;Wei Yang

文献摘要

相似文献

神经图像字幕生成(NICG)模型由于其在视觉理解方面的优异表现而受到研究界的广泛关注。现有的工作主要集中在提高NICG模型的精度,而效率的探索较少。然而,许多实际应用需要实时反馈,这高度依赖于NICG模型的效率。最近的研究表明,NICG模型的效率可能会因不同的输入而异。这一观察带来了NICG模型的新攻击面,即,攻击者可能会稍微改变输入,导致NICG模型消耗更多的计算资源。为了进一步理解这种效率导向的威胁,我们提出了一种新的攻击方法,NICGSlowDown,以评估NICG模型的效率鲁棒性。我们的实验结果表明,NICGSlowDown可以生成具有人类不可察觉的扰动的图像,这将使NICG模型延迟增加高达483.86%。我们希望这项研究可以提高社会各界对NICG模型的效率鲁棒性的关注。
Neural image caption generation (NICG) models have received massive attention from the research community due to their excellent performance in visual understanding. Existing work focuses on improving NICG model ac-curacy while efficiency is less explored. However, many real-world applications require real-time feedback, which highly relies on the efficiency of NICG models. Recent re-search observed that the efficiency of NICG models could vary for different inputs. This observation brings in a new attack surface of NICG models, i.e., An adversary might be able to slightly change inputs to cause the NICG mod-els to consume more computational resources. To further understand such efficiency-oriented threats, we propose a new attack approach, NICGSlowDown, to evaluate the ef-ficiency robustness of NICG models. Our experimental re-sults show that NICGSlowDown can generate images with human-unnoticeable perturbations that will increase the NICG model latency up to 483.86%. We hope this research could raise the community's concern about the efficiency robustness of NICG models.